PT-2024-38924 · Unknown · Kitsada8621 Digital Library Management System

Zihe

·

Published

2024-08-29

·

Updated

2024-09-02

·

CVE-2024-8297

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: kitsada8621 Digital Library Management System version 1.0
Description: A vulnerability was found in the kitsada8621 Digital Library Management System. It has been classified as problematic and affects the function JwtRefreshAuth of the file middleware/jwt refresh token middleware.go. The manipulation of the argument Authorization leads to improper output neutralization for logs. It is possible to launch the attack remotely.
Recommendations: To fix this issue, apply the patch 81b3336b4c9240f0bf50c13cb8375cf860d945f1 to the kitsada8621 Digital Library Management System version 1.0. As a temporary workaround, consider disabling the JwtRefreshAuth function until the patch is applied. Restrict access to the middleware/jwt refresh token middleware.go file to minimize the risk of exploitation. Avoid using the Authorization argument in the affected API endpoint until the issue is resolved.

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2024-8297

Affected Products

Kitsada8621 Digital Library Management System