PT-2024-34264 · Maantheme · Maanstore Api

Stealthcopter

·

Published

2024-10-28

·

Updated

2024-10-31

·

CVE-2024-50487

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: MaanStore API versions n/a through 1.0.1
Description: The issue is related to an Authentication Bypass Using an Alternate Path or Channel vulnerability in the MaanTheme MaanStore API, allowing unauthorized access.
Recommendations: For MaanStore API versions n/a through 1.0.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2024-50487

Affected Products

Maanstore Api