This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter dfclientid through API request URLs which could lead to unauthorized access to sensitive information belonging to other users.
History

Wed, 16 Oct 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Shilpisoft
Shilpisoft net Back Office
CPEs cpe:2.3:a:shilpisoft:net_back_office:*:*:*:*:*:*:*:*
Vendors & Products Shilpisoft
Shilpisoft net Back Office
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Fri, 04 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Oct 2024 13:00:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter dfclientid through API request URLs which could lead to unauthorized access to sensitive information belonging to other users.
Title Improper Access Control Vulnerability
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2024-10-04T12:30:46.271Z

Updated: 2024-10-04T13:34:28.648Z

Reserved: 2024-09-30T11:42:54.095Z

Link: CVE-2024-47657

cve-icon Vulnrichment

Updated: 2024-10-04T13:34:24.686Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-04T13:15:12.023

Modified: 2024-10-16T15:44:16.807

Link: CVE-2024-47657

cve-icon Redhat

No data.