PT-2024-20516 · Unknown · Latepoint Plugin
Gharib Sharifi
+1
·
Published
2024-06-14
·
Updated
2024-06-17
·
CVE-2024-2472
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
LatePoint Plugin versions up to and including 4.9.9
Description
The issue is related to a missing capability check on the
start or use session for customer function, allowing unauthorized access and modification of data. This enables unauthenticated attackers to view other customers' cabinets, including sensitive information such as email addresses, and change their LatePoint user password.Recommendations
For versions up to and including 4.9.9, update to a version that includes a capability check on the
start or use session for customer function to prevent unauthorized access and modification of data. As a temporary workaround, consider restricting access to the start or use session for customer function until a patch is available.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Latepoint Plugin