CVE-2024-47652

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Oct 4, 2024
Updated: Oct 16, 2024
CWE ID 308

Summary

CVE-2024-47652 is a newly identified cybersecurity vulnerability affecting the Shilpi Client Dashboard. The issue arises from an inadequate authentication mechanism in the login module, which grants access to any user account using only their corresponding mobile number. This weakness exposes a significant risk, as a remote attacker could successfully exploit it by providing the mobile number of a targeted user, thereby gaining unauthorized access to that user's account.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share