A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. 

When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy.  The ticket requester can be changed from the original requester to another user in the same application,
which the application then accepts.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-50613 A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user.  When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy.  The ticket requester can be changed from the original requester to another user in the same application, which the application then accepts.
Fixes

Solution

Ensure the Issuetrak application is updated to version 17.2 or later.


Workaround

No workaround given by the vendor.

History

Wed, 04 Dec 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Dec 2024 03:45:00 +0000

Type Values Removed Values Added
Description A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user.  When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy.  The ticket requester can be changed from the original requester to another user in the same application, which the application then accepts.
Title Unauthorized Modification of Ticket Requester
Weaknesses CWE-472
CWE-837
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Gridware

Published:

Updated: 2024-12-04T14:09:11.911Z

Reserved: 2024-12-03T23:13:54.977Z

Link: CVE-2024-12123

cve-icon Vulnrichment

Updated: 2024-12-04T14:05:31.553Z

cve-icon NVD

Status : Received

Published: 2024-12-04T04:15:04.430

Modified: 2024-12-04T04:15:04.430

Link: CVE-2024-12123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.