PT-2024-16002 · Shanxi Diankeyun Technology · Noderp
Glzjin
·
Published
2024-01-29
·
Updated
2024-05-17
·
CVE-2024-1006
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Shanxi Diankeyun Technology NODERP versions up to 6.0.2
Description
A critical issue affects the Cookie Handler component, specifically the file application/index/common.php, due to improper authentication when manipulating the
Nod User Id/Nod User Token argument. This can be exploited remotely.Recommendations
For versions up to 6.0.2, consider disabling the Cookie Handler component or restricting access to the
application/index/common.php file until a patch is available. Additionally, avoid using the Nod User Id and Nod User Token arguments in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Noderp