PT-2024-39150 · Unknown · Netcat Cms

·

CVE-2024-8651

·

Published

2024-09-19

·

Updated

2024-09-23

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: NetCat CMS versions 6.4.0.24126.2 through 6.4.0.24247
Description: A vulnerability in NetCat CMS allows an attacker to send a specially crafted HTTP request to check whether a user exists in the system. This issue could be a basis for further attacks. The estimated number of potentially affected devices is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations: For NetCat CMS versions 6.4.0.24126.2 through 6.4.0.24247, apply the patch from the vendor. Versions 6.4.0.24248 and later have the patch applied. As a temporary workaround, consider restricting access to the HTTP request functionality until the patch is applied.

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8651

Affected Products

Netcat Cms