PT-2025-18712 · Sematell · Sematell Replyone

Published

2025-05-01

·

Updated

2025-05-03

·

CVE-2024-48905

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Sematell ReplyOne version 7.4.3.0
Description The issue concerns insecure permissions for the "/rest/sessions" endpoint. This could potentially allow unauthorized access or actions.
Recommendations For Sematell ReplyOne version 7.4.3.0, consider restricting access to the "/rest/sessions" endpoint until a fix is available. Review and adjust the permissions settings to ensure they align with the principle of least privilege, minimizing potential risks associated with insecure permissions.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-48905

Affected Products

Sematell Replyone