PT-2024-31241 · Mgt Commerce Gmbh · Cloudpanel

Muhammad Aizat

·

Published

2024-11-08

·

Updated

2024-11-18

·

CVE-2024-44765

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MGT-COMMERCE GmbH CloudPanel versions 2.0.0 through 2.4.2
Description An Improper Authorization (Access Control Misconfiguration) issue allows low-privilege users to bypass access controls, gaining unauthorized access to sensitive configuration files and administrative functionality. This enables attackers to escalate privileges.
Recommendations For versions 2.0.0 through 2.4.2, update to a version that fixes the Improper Authorization issue to prevent low-privilege users from bypassing access controls. As a temporary workaround, consider restricting access to sensitive configuration files and administrative functionality until a patch is available.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-44765

Affected Products

Cloudpanel