Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3570 | Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or access restricted data without proper authorization. The lack of server-side validation exacerbates the issue, as the application relies on client-side information for authentication. |
Github GHSA |
GHSA-995c-qww8-64fj | Oqtane Framework Incorrect Access Control vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-290 | |
| Metrics |
cvssV3_1
|
Fri, 20 Dec 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or access restricted data without proper authorization. The lack of server-side validation exacerbates the issue, as the application relies on client-side information for authentication. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-20T17:25:33.514Z
Reserved: 2024-12-06T00:00:00
Link: CVE-2024-55470
Updated: 2024-12-20T17:25:24.138Z
Status : Received
Published: 2024-12-20T16:15:23.977
Modified: 2024-12-20T18:15:30.370
Link: CVE-2024-55470
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA