PT-2024-23861 · Unknown · Changing Mobile

Vtim

·

Published

2024-07-01

·

Updated

2024-07-01

·

CVE-2024-3122

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CHANGING Mobile (affected versions not specified)
Description The issue concerns the Mobile One Time Password functionality, which does not properly filter parameters for the file download feature. This allows remote attackers with administrator privileges to read arbitrary files on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2024-3122

Affected Products

Changing Mobile