PT-2024-32711 · Unknown · Shilpi Client Dashboard
Mohit Gadiya
·
Published
2024-10-04
·
Updated
2024-10-16
·
CVE-2024-47652
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Shilpi Client Dashboard (affected versions not specified)
Description
The issue is related to an inadequate authentication mechanism in the login module of the Shilpi Client Dashboard. This allows access to any user's account with just their corresponding mobile number. A remote attacker could exploit this by providing the mobile number of the targeted user to obtain complete access to the targeted user's account.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shilpi Client Dashboard