Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.
CVSS
No CVSS.
References
Link | Resource |
---|---|
http://financials.com | Broken Link |
http://financials.com | Broken Link |
http://unit4.com | Product |
http://unit4.com | Product |
https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html | Exploit Third Party Advisory |
https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html | Exploit Third Party Advisory |
https://www.unit4.com/ | Product |
https://www.unit4.com/ | Product |
https://www.unit4.com/products/financial-management-software | Product |
https://www.unit4.com/products/financial-management-software | Product |
Configurations
History
17 Jun 2025, 13:25
Type | Values Removed | Values Added |
---|---|---|
First Time |
Unit4
Unit4 financials By Coda |
|
CPE | cpe:2.3:a:unit4:financials_by_coda:*:*:*:*:*:*:*:* | |
References | () https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html - Exploit, Third Party Advisory | |
References | () https://www.unit4.com/ - Product | |
References | () http://unit4.com - Product | |
References | () https://www.unit4.com/products/financial-management-software - Product | |
References | () http://financials.com - Broken Link |
25 Apr 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 Apr 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
Summary | Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request. |
20 Mar 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-20 15:15
Updated : 2025-06-17 13:25
NVD link : CVE-2024-28735
Mitre link : CVE-2024-28735
JSON object : View
Products Affected
unit4
- financials_by_coda
CWE
No CWE.