PT-2024-39123 · Techexcel · Techexcel Back Office

·

CVE-2024-8601

·

Published

2024-09-09

·

Updated

2024-09-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: TechExcel Back Office Software versions prior to 1.0.0
Description: This issue exists due to improper access controls on certain API endpoints, allowing an authenticated remote attacker to exploit the vulnerability by manipulating a parameter through the API request URL. This could lead to unauthorized access to sensitive information belonging to other users.
Recommendations: For versions prior to 1.0.0, update to version 1.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive API endpoints until a patch is available. Avoid using manipulated parameters in API requests to minimize the risk of exploitation.

Fix

Incorrect Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8601

Affected Products

Techexcel Back Office