CVE-2024-55470

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 20, 2024
CWE ID 290

Summary

CVE-2024-55470 is a newly identified vulnerability affecting Oqtane Framework version 6.0.0. This issue involves Incorrect Access Control, allowing attackers to bypass passcode validation by manipulating the entityid parameter. As a result, they can gain unauthorized access to the application or restricted data. The concerning aspect of this vulnerability is that the application fails to validate server-side, relying solely on client-side information for authentication.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share