This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request body leading to unauthorized modification of requests belonging to the other users.
History

Wed, 16 Oct 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Shilpisoft
Shilpisoft client Dashboard
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*
Vendors & Products Shilpisoft
Shilpisoft client Dashboard
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Fri, 04 Oct 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Oct 2024 12:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request body leading to unauthorized modification of requests belonging to the other users.
Title Missing Authorization Vulnerability
Weaknesses CWE-266
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2024-10-04T12:15:44.442Z

Updated: 2024-10-04T14:11:03.202Z

Reserved: 2024-09-30T11:42:54.095Z

Link: CVE-2024-47653

cve-icon Vulnrichment

Updated: 2024-10-04T14:10:57.688Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-04T13:15:11.563

Modified: 2024-10-16T15:13:52.280

Link: CVE-2024-47653

cve-icon Redhat

No data.