CVE-2024-39033
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-39033 is a vulnerability affecting Newgensoft OmniDocs 11.0_SP1_03_006. This issue involves an Insecure Direct Object Reference (IDOR) in the getuserproperty function, which grants unauthorized access to users' configuration settings and potentially sensitive Personal Identifiable Information (PII). An attacker can exploit this vulnerability by manipulating the object reference ID, allowing them to access and steal data that is not intended for their access. This idiosyncrasy poses a significant risk to the confidentiality and integrity of the impacted system. Organizations using the affected version of Newgensoft OmniDocs are advised to apply the necessary patches to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.