CVE-2024-47316

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Oct 5, 2024
Updated: Oct 7, 2024
CWE ID 639

Summary

CVE-2024-47316 is a newly disclosed vulnerability affecting the Salon booking system. This authorization bypass issue is rooted in a user-controlled key vulnerability. The Salon booking system, which is used for managing appointments and customer data, is susceptible to this flaw from version n/a through 10.9. An attacker who successfully exploits this vulnerability can bypass security restrictions and gain unauthorized access to sensitive information, potentially resulting in data breaches and unintended modifications. Users are advised to update their systems as soon as a patch becomes available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share