EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive data without login.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-23539 | EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive data without login. |
Fixes
Solution
Update to 3.x or later version.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7676-9418d-1.html |
|
History
Thu, 23 Jan 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ebmtech
Ebmtech risweb |
|
| CPEs | cpe:2.3:a:ebmtech:risweb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ebmtech
Ebmtech risweb |
Mon, 14 Oct 2024 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Mon, 14 Oct 2024 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ebm Technologies
Ebm Technologies risweb |
|
| CPEs | cpe:2.3:a:ebm_technologies:risweb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ebm Technologies
Ebm Technologies risweb |
|
| Metrics |
ssvc
|
Mon, 14 Oct 2024 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 |
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-10-14T06:13:18.118Z
Reserved: 2024-02-15T01:33:48.680Z
Link: CVE-2024-26263
Updated: 2024-08-02T00:07:19.335Z
Status : Analyzed
Published: 2024-02-15T03:15:35.530
Modified: 2025-01-23T17:39:42.940
Link: CVE-2024-26263
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD