PT-2024-27836 · Themesphere · Themesphere Smartmag

Justakazh

·

Published

2024-08-12

·

Updated

2024-09-12

·

CVE-2024-37930

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ThemeSphere SmartMag versions prior to 9.3.0
Description The issue is related to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization vulnerability. It allows excavation and accessing functionality not properly constrained by ACLs.
Recommendations For versions prior to 9.3.0, update to version 9.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and functionality to minimize the risk of exploitation.

Fix

Missing Authorization

Information Disclosure

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2024-37930

Affected Products

Themesphere Smartmag