PT-2024-5518 · Unknown · Exacqvision Web Service
Diego Zaffaroni
·
Published
2024-08-01
·
Updated
2024-08-09
·
CVE-2024-32862
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ExacqVision Web Services (affected versions not specified)
Description
The issue is related to the ExacqVision Web Services, which under certain circumstances does not provide sufficient protection from untrusted domains. This is due to incorrect handling of the HTTP
Origin header in the Cross-Origin Resource Sharing (CORS) mechanism of the exacqVision Web Service system. Exploitation of this issue may allow a remote attacker to bypass security restrictions and perform cross-site scripting attacks.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Exacqvision Web Service