CVE-2024-47651

This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple “userid” parameters in the API request body leading to unauthorized access of sensitive information belonging to other users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:shilpi:client_dashboard:*:*:*:*:*:*:*:*

History

10 Oct 2024, 21:01

Type Values Removed Values Added
CWE CWE-235 NVD-CWE-Other
CPE cpe:2.3:a:shilpi:client_dashboard:*:*:*:*:*:*:*:*
References () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 - () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Shilpi client Dashboard
Shilpi

04 Oct 2024, 13:50

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-04 12:15

Updated : 2024-10-10 21:01


NVD link : CVE-2024-47651

Mitre link : CVE-2024-47651


JSON object : View

Products Affected

shilpi

  • client_dashboard