PT-2024-31584 · Unknown · Janto Ticketing

Alejandro Amorín Niño

·

Published

2024-05-07

·

Updated

2024-05-07

·

CVE-2024-4537

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Janto Ticketing Software version 4.3r10
Description The issue allows a remote user to obtain the download URL of another user, potentially enabling them to access purchased tickets.
Recommendations For Janto Ticketing Software version 4.3r10, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4537

Affected Products

Janto Ticketing