PT-2024-31588 · Unknown · Janto Ticketing

Alejandro Amorín Niño

·

Published

2024-05-07

·

Updated

2024-05-07

·

CVE-2024-4538

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Janto Ticketing Software version 4.3r10
Description The issue allows a remote user to obtain a user's event ticket by creating a specific request with the ticket reference ID, leading to the exposure of sensitive user data. This is due to an Insecure Direct Object Reference (IDOR) vulnerability.
Recommendations For version 4.3r10, consider restricting access to the ticket reference ID to prevent unauthorized access to event tickets until a patch is available. As a temporary workaround, avoid using the ticket reference ID in requests to minimize the risk of exploitation.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4538

Affected Products

Janto Ticketing