Description
SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash
No analysis available yet.
Remediation
Vendor Solution
Upgrade to version 23.3.38 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-24968 | SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash |
References
| Link | Providers |
|---|---|
| https://www.gov.il/en/Departments/faq/cve_advisories |
|
History
No history.
Status: PUBLISHED
Assigner: INCD
Published:
Updated: 2024-08-02T00:41:54.967Z
Reserved: 2024-02-26T09:27:55.323Z
Link: CVE-2024-27775
Updated: 2024-08-02T00:41:54.967Z
Status : Deferred
Published: 2024-03-28T13:15:47.340
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-27775
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:21:44Z
Weaknesses
EUVD