PT-2024-39123 · Techexcel · Techexcel Back Office

Mohit Gadiya

·

Published

2024-09-09

·

Updated

2024-09-17

·

CVE-2024-8601

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: TechExcel Back Office Software versions prior to 1.0.0
Description: This issue exists due to improper access controls on certain API endpoints, allowing an authenticated remote attacker to exploit the vulnerability by manipulating a parameter through the API request URL. This could lead to unauthorized access to sensitive information belonging to other users.
Recommendations: For versions prior to 1.0.0, update to version 1.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive API endpoints until a patch is available. Avoid using manipulated parameters in API requests to minimize the risk of exploitation.

Fix

Incorrect Authorization

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-8601

Affected Products

Techexcel Back Office