PT-2024-20105 · Vantage6 · Vantage6

Bartvanb

·

Published

2024-03-14

·

Updated

2025-08-06

·

CVE-2024-23823

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions vantage6 (affected versions not specified)
Description The vantage6 server has no restrictions on CORS settings, which should be configurable to set allowed origins. The impact is limited because v6 does not use session cookies.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-23823
GHSA-4946-85PR-FVXH

Affected Products

Vantage6