PT-2024-33280 · Zimaos · Zimaos
Drdark1999
·
Published
2024-10-24
·
Updated
2024-11-06
·
CVE-2024-48932
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ZimaOS versions 1.2.4 and earlier
Description
The issue allows unauthenticated users to access sensitive information, such as usernames, through the API endpoint
http://<Server-ip>/v1/users/name without any authorization. This could be exploited by an attacker to enumerate usernames and leverage them for further attacks, such as brute-force or phishing campaigns.Recommendations
For ZimaOS versions 1.2.4 and earlier, as a temporary workaround, consider restricting access to the API endpoint
http://<Server-ip>/v1/users/name to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Access Control
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zimaos