This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple “userid” parameters in the API request body leading to unauthorized access of sensitive information belonging to other users.
History

Thu, 10 Oct 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Shilpi
Shilpi client Dashboard
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:shilpi:client_dashboard:*:*:*:*:*:*:*:*
Vendors & Products Shilpi
Shilpi client Dashboard
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Fri, 04 Oct 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Oct 2024 12:15:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple “userid” parameters in the API request body leading to unauthorized access of sensitive information belonging to other users.
Title Parameter Pollution Vulnerability
Weaknesses CWE-235
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2024-10-04T12:07:45.980Z

Updated: 2024-10-04T14:12:59.399Z

Reserved: 2024-09-30T11:42:54.095Z

Link: CVE-2024-47651

cve-icon Vulnrichment

Updated: 2024-10-04T14:12:53.785Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-04T12:15:12.710

Modified: 2024-10-10T21:01:39.413

Link: CVE-2024-47651

cve-icon Redhat

No data.