Lucene search

K
cveTR-CERTCVE-2024-1153
HistoryJun 27, 2024 - 2:15 p.m.

CVE-2024-1153

2024-06-2714:15:12
CWE-284
TR-CERT
web.nvd.nist.gov
28
access control
talya informatics
travel apps
security levels
exploiting
incorrectly configured

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

20.9%

Improper Access Control vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel APPS: before v17.0.68.

Affected configurations

Nvd
Node
talyabilisimtravel_appsRange<17.0.68
VendorProductVersionCPE
talyabilisimtravel_apps*cpe:2.3:a:talyabilisim:travel_apps:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Travel APPS",
    "vendor": "Talya Informatics",
    "versions": [
      {
        "lessThan": "v17.0.68",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

20.9%

Related for CVE-2024-1153