CVE-2024-0949

Improper Access Control, Missing Authorization, Incorrect Authorization, Incorrect Permission Assignment for Critical Resource, Missing Authentication, Weak Authentication, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Talya Informatics Elektraweb allows Exploiting Incorrectly Configured Access Control Security Levels, Manipulating Web Input to File System Calls, Embedding Scripts within Scripts, Malicious Logic Insertion, Modification of Windows Service Configuration, Malicious Root Certificate, Intent Spoof, WebView Exposure, Data Injected During Configuration, Incomplete Data Deletion in a Multi-Tenant Environment, Install New Service, Modify Existing Service, Install Rootkit, Replace File Extension Handlers, Replace Trusted Executable, Modify Shared File, Add Malicious File to Shared Webroot, Run Software at Logon, Disable Security Software.This issue affects Elektraweb: before v17.0.68.
Configurations

No configuration.

History

27 Jun 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-27 10:15

Updated : 2024-06-27 12:47


NVD link : CVE-2024-0949

Mitre link : CVE-2024-0949


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization

CWE-306

Missing Authentication for Critical Function

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints

CWE-1390

Weak Authentication

CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-863

Incorrect Authorization

CWE-284

Improper Access Control