Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arbitrary files, potentially leading to Remote Code Execution.
History

Tue, 29 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Moneymanagerex
Moneymanagerex money Manager Ex Webapp
Weaknesses CWE-863
CPEs cpe:2.3:a:moneymanagerex:money_manager_ex_webapp:*:*:*:*:*:*:*:*
Vendors & Products Moneymanagerex
Moneymanagerex money Manager Ex Webapp
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Oct 2024 22:00:00 +0000

Type Values Removed Values Added
Description Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arbitrary files, potentially leading to Remote Code Execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-24T00:00:00

Updated: 2024-10-29T17:02:54.530Z

Reserved: 2024-07-18T00:00:00

Link: CVE-2024-41617

cve-icon Vulnrichment

Updated: 2024-10-29T17:02:47.155Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-24T22:15:03.687

Modified: 2024-10-29T17:35:07.133

Link: CVE-2024-41617

cve-icon Redhat

No data.