PT-2024-15607 · Unknown · Huaxia Erp

Puppy

·

Published

2024-01-13

·

Updated

2024-05-17

·

CVE-2024-0490

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Huaxia ERP versions up to 3.1
Description A problematic issue affects some unknown processing of the file /user/getAllList, leading to information disclosure. The attack may be initiated remotely.
Recommendations For Huaxia ERP versions up to 3.1, upgrade to version 3.2 to address this issue. As a temporary workaround, consider restricting access to the /user/getAllList file until the upgrade is applied.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-0490

Affected Products

Huaxia Erp