PT-2025-2677 · Unknown · Aims Ecrew

Published

2025-01-07

·

Updated

2025-01-08

·

CVE-2024-44450

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AIMS eCrew versions prior to JUN23 #190
Description Multiple functions in AIMS eCrew are vulnerable to Authorization Bypass. The issue was fixed in version JUN23 #190.
Recommendations For versions prior to JUN23 #190, update to version JUN23 #190 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable functions until the update is applied.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-44450

Affected Products

Aims Ecrew