An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access to sensitive configuration files and administrative functionality.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.01032}

epss

{'score': 0.01144}


Mon, 18 Nov 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mgt-commerce
Mgt-commerce cloudpanel
Weaknesses CWE-863
CPEs cpe:2.3:a:mgt-commerce:cloudpanel:-:*:*:*:*:*:*:*
Vendors & Products Mgt-commerce
Mgt-commerce cloudpanel
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 Nov 2024 23:30:00 +0000

Type Values Removed Values Added
Description An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH v2.0.0 to v2.4.2 allows attackers to escalate privileges and access sensitive information via manipulation of the Nginx configuration file. An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access to sensitive configuration files and administrative functionality.

Fri, 08 Nov 2024 19:00:00 +0000

Type Values Removed Values Added
Description An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH v2.0.0 to v2.4.2 allows attackers to escalate privileges and access sensitive information via manipulation of the Nginx configuration file.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-18T14:03:37.382Z

Reserved: 2024-08-21T00:00:00

Link: CVE-2024-44765

cve-icon Vulnrichment

Updated: 2024-11-18T14:03:15.521Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-08T19:15:05.590

Modified: 2024-11-18T14:35:03.200

Link: CVE-2024-44765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.