PT-2024-21316 · Ebm Technologies · Ebm Technologies Risweb

Published

2024-02-14

·

Updated

2024-10-14

·

CVE-2024-26263

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions EBM Technologies RISWEB (affected versions not specified)
Description The issue concerns a lack of proper permission control for specific URL paths in EBM Technologies RISWEB, allowing attackers to browse certain pages and query sensitive data without logging in.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-26263

Affected Products

Ebm Technologies Risweb