This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their corresponding mobile number. A remote attacker could exploit this vulnerability by providing mobile number of targeted user, to obtain complete access to the targeted user account.
History

Wed, 16 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-Other
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 04 Oct 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Shilpisoft
Shilpisoft client Dashboard
CPEs cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*
Vendors & Products Shilpisoft
Shilpisoft client Dashboard
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Oct 2024 12:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their corresponding mobile number. A remote attacker could exploit this vulnerability by providing mobile number of targeted user, to obtain complete access to the targeted user account.
Title Insecure Authentication Vulnerability
Weaknesses CWE-308
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2024-10-04T12:13:22.614Z

Updated: 2024-10-04T14:12:13.841Z

Reserved: 2024-09-30T11:42:54.095Z

Link: CVE-2024-47652

cve-icon Vulnrichment

Updated: 2024-10-04T14:11:59.229Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-04T13:15:11.417

Modified: 2024-10-16T14:12:06.307

Link: CVE-2024-47652

cve-icon Redhat

No data.