PT-2024-18172 · Nt Ware+1 · Uniflow Online+1
Published
2024-09-02
·
Updated
2024-09-17
·
CVE-2024-1621
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
uniFLOW Online versions prior to and including 2024.1.0
Description
The registration process of uniFLOW Online apps can be compromised when email login is enabled on the tenant, particularly for those utilizing email login in combination with Microsoft Safe Links or similar. This issue may allow an attacker to register themselves against a genuine user in the system, granting malicious users similar access and capabilities via the app to the existing genuine user.
Recommendations
For versions prior to and including 2024.1.0, consider disabling email login on the tenant until a patch is available. Restrict access to the registration process to minimize the risk of exploitation. Avoid using email login in combination with Microsoft Safe Links or similar until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Safe Links
Uniflow Online