PT-2024-39123 · Techexcel · Techexcel Back Office
Mohit Gadiya
·
Published
2024-09-09
·
Updated
2024-09-17
·
CVE-2024-8601
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
TechExcel Back Office Software versions prior to 1.0.0
Description:
This issue exists due to improper access controls on certain API endpoints, allowing an authenticated remote attacker to exploit the vulnerability by manipulating a parameter through the API request URL. This could lead to unauthorized access to sensitive information belonging to other users.
Recommendations:
For versions prior to 1.0.0, update to version 1.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive API endpoints until a patch is available. Avoid using manipulated parameters in API requests to minimize the risk of exploitation.
Fix
Incorrect Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Techexcel Back Office