PT-2024-39246 · Syscom · Omflow

Sideman

·

Published

2024-09-15

·

Updated

2024-09-20

·

CVE-2024-8780

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: OMFLOW from The SYSCOM Group (affected versions not specified)
Description: The issue is related to the data query functionality in OMFLOW, which does not properly restrict the query range. This allows remote attackers with regular privileges to obtain accounts and password hashes of other users.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-8780

Affected Products

Omflow