PT-2026-21798 · Unknown · Eventsentry

·

CVE-2026-24443

·

Publicado

2026-02-24

·

Atualizado

2026-02-25

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EventSentry versions prior to 6.0.1.20
Description EventSentry has a flaw where passwords can be changed without verifying the current password through the account management functionality within the Web Reports interface. An attacker gaining access to an authenticated user session can modify the account password without knowing the original credentials. This allows for persistent account takeover, potentially leading to privilege escalation if administrative accounts are compromised.
Recommendations Update EventSentry to version 6.0.1.20 or later.

Correção

LPE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24443

Produtos afetados

Eventsentry