CVE-2024-7921

A vulnerability has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /report/ParkOutRecord/GetDataList. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://vuldb.com/?ctiid.275071 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.275071 Third Party Advisory VDB Entry
https://vuldb.com/?submit.387126 Third Party Advisory VDB Entry
https://wiki.shikangsi.com/post/share/7d5eb025-1c30-44b4-b609-61938f6d6c05 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:jielink\+_jsotc2016_project:jielink\+_jsotc2016:*:*:*:*:*:*:*:*

History

21 Aug 2024, 12:34

Type Values Removed Values Added
CWE NVD-CWE-Other
First Time Jielink\+ Jsotc2016 Project jielink\+ Jsotc2016
Jielink\+ Jsotc2016 Project
References () https://vuldb.com/?ctiid.275071 - () https://vuldb.com/?ctiid.275071 - Permissions Required, Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.275071 - () https://vuldb.com/?id.275071 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.387126 - () https://vuldb.com/?submit.387126 - Third Party Advisory, VDB Entry
References () https://wiki.shikangsi.com/post/share/7d5eb025-1c30-44b4-b609-61938f6d6c05 - () https://wiki.shikangsi.com/post/share/7d5eb025-1c30-44b4-b609-61938f6d6c05 - Exploit, Third Party Advisory
CVSS v2 : 4.0
v3 : 4.3
v2 : 4.0
v3 : 9.8
CPE cpe:2.3:a:jielink\+_jsotc2016_project:jielink\+_jsotc2016:*:*:*:*:*:*:*:*

19 Aug 2024, 12:59

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido encontrada en Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 hasta 20240805 y clasificada como problemática. Una funcionalidad desconocida del archivo /report/ParkOutRecord/GetDataList es afectada por esta vulnerabilidad. La manipulación conduce a controles de acceso inadecuados. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al público y puede utilizarse.

19 Aug 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-19 03:15

Updated : 2024-08-21 12:34


NVD link : CVE-2024-7921

Mitre link : CVE-2024-7921

CVE.ORG link : CVE-2024-7921


JSON object : View

Products Affected

jielink\+_jsotc2016_project

  • jielink\+_jsotc2016
CWE
NVD-CWE-Other CWE-284

Improper Access Control