CVE-2024-47085

This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apexsoftcell:ld_geo:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:apexsoftcell:ld_dp_back_office:*:*:*:*:*:*:*:*

History

26 Sep 2024, 15:30

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-359 NVD-CWE-Other
CPE cpe:2.3:a:apexsoftcell:ld_geo:*:*:*:*:*:*:*:*
cpe:2.3:a:apexsoftcell:ld_dp_back_office:*:*:*:*:*:*:*:*
First Time Apexsoftcell ld Dp Back Office
Apexsoftcell ld Geo
Apexsoftcell
References () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0296 - () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0296 - Third Party Advisory

20 Sep 2024, 13:15

Type Values Removed Values Added
Summary This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users. This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.

19 Sep 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-19 06:15

Updated : 2024-09-26 15:30


NVD link : CVE-2024-47085

Mitre link : CVE-2024-47085


JSON object : View

Products Affected

apexsoftcell

  • ld_geo
  • ld_dp_back_office