Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user with greater privileges having access to the functionalities of the user that the code was copied.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Jan 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-384 | |
Metrics |
cvssV3_1
|
Thu, 31 Oct 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking. | Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user with greater privileges having access to the functionalities of the user that the code was copied. |
Wed, 30 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Netadmin
Netadmin netadmin |
|
Weaknesses | CWE-384 | |
CPEs | cpe:2.3:a:netadmin:netadmin:*:*:*:*:*:*:*:* | |
Vendors & Products |
Netadmin
Netadmin netadmin |
|
Metrics |
cvssV3_1
|
Tue, 29 Oct 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-29T00:00:00
Updated: 2025-01-09T17:25:23.481Z
Reserved: 2024-10-10T00:00:00
Link: CVE-2024-48955
Vulnrichment
Updated: 2024-10-30T15:10:36.718Z
NVD
Status : Awaiting Analysis
Published: 2024-10-29T18:15:05.690
Modified: 2025-01-09T18:15:29.147
Link: CVE-2024-48955
Redhat
No data.