PT-2024-7861 · Unknown · Orchid Platform

Catferq

·

Published

2024-10-29

·

Updated

2024-11-12

·

CVE-2024-51992

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Orchid Platform versions 8 through 14.42.x
Description The issue is a method exposure problem in the Orchid Platform’s asynchronous modal functionality, allowing attackers to call arbitrary methods within the Screen class. This could lead to brute force attacks on database tables, validation checks against user credentials, and disclosure of the server’s real IP address.
Recommendations For Orchid Platform versions 8 through 14.42.x, upgrade to version 14.43.0 or later to address this issue. If upgrading to version 14.43.0 is not immediately possible, implement middleware to intercept and validate requests to asynchronous modal endpoints, allowing only approved methods and parameters, such as the provided example middleware PreventBruteForceOnAsyncRoute.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-09363
CVE-2024-51992
GHSA-CM46-GQF4-MV4F

Affected Products

Orchid Platform