PT-2024-5518 · Unknown · Exacqvision Web Service

Diego Zaffaroni

·

Published

2024-08-01

·

Updated

2024-08-09

·

CVE-2024-32862

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ExacqVision Web Services (affected versions not specified)
Description The issue is related to the ExacqVision Web Services, which under certain circumstances does not provide sufficient protection from untrusted domains. This is due to incorrect handling of the HTTP Origin header in the Cross-Origin Resource Sharing (CORS) mechanism of the exacqVision Web Service system. Exploitation of this issue may allow a remote attacker to bypass security restrictions and perform cross-site scripting attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-06167
CVE-2024-32862

Affected Products

Exacqvision Web Service