PT-2026-99759 · Нпо Ритм · Georitm
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ООО НПО Ритм GEOritm versions prior to 2.46
Description
A flaw in the REST API component allows remote attackers to bypass authentication. By manipulating the
objectId argument within the '/restapi/objects/obj-groups' endpoint, an unauthorized user can gain access to the system.Recommendations
Update to version 2.46.
Exploit
Fix
Improper Authentication
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Georitm