PT-2024-16534 · Crown · Crown

Manuel Stotz

+2

·

Published

2024-12-06

·

Updated

2024-12-06

·

CVE-2024-10774

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions CROWN (affected versions not specified)
Description The issue allows unauthenticated access to critical functions through CROWN APIs, making large parts of the web application accessible without authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10774

Affected Products

Crown