PT-2025-6445 · Unknown · Majestic Support

Tim Coen

·

Published

2025-02-12

·

Updated

2025-02-12

·

CVE-2024-13601

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin versions 1.0.5 and earlier
Description The issue is related to Insecure Direct Object Reference. It affects the 'exportusereraserequest' function due to missing validation on a user-controlled key. This allows authenticated attackers with Subscriber-level access and above to export ticket data for any user.
Recommendations For versions 1.0.5 and earlier, consider disabling the 'exportusereraserequest' function until a patch is available to prevent unauthorized data export. Restrict access to the vulnerable function to minimize the risk of exploitation. Avoid using the affected function for sensitive data handling until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13601

Affected Products

Majestic Support