Lucene search

K
vulnrichmentCERT-InVULNRICHMENT:CVE-2024-8601
HistorySep 09, 2024 - 9:13 a.m.

CVE-2024-8601 Improper Access Control Vulnerability in TechExcel Back Office Software

2024-09-0909:13:24
CWE-639
CERT-In
github.com
5
techexcel back office
access control
vulnerability
api
unauthorized access

CVSS4

8.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:L/VI:N/SI:N/VA:N/SA:N

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

18.8%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to unauthorized access to sensitive information belonging to other users.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:techexcel_inc.:back_office:*:*:*:*:*:*:*:*"
    ],
    "vendor": "techexcel_inc.",
    "product": "back_office",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "1.0.0",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS4

8.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:L/VI:N/SI:N/VA:N/SA:N

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

18.8%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-8601