PT-2024-30377 · Mycred · Mycred

Mika

·

Published

2024-08-26

·

Updated

2024-09-12

·

CVE-2024-43214

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions myCred versions 2.6.x through 2.7.2
Description The issue is related to a Missing Authorization vulnerability in myCred. This vulnerability may expose sensitive data. Users are urged to upgrade to mitigate the risk.
Recommendations For versions 2.6.x through 2.7.2, upgrade to version 2.7.3 to resolve the issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-43214

Affected Products

Mycred