CVE-2024-12123
CVSS V2 None
CVSS V3 None
Description
A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user.
When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy. The ticket requester can be changed from the original requester to another user in the same application,
which the application then accepts.
Overview
- CVE ID
- CVE-2024-12123
- Assigner
- Gridware
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-12-04T03:26:00.918Z
- Last Modified Date
- 2024-12-04T03:26:00.918Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://helpcenter.issuetrak.com/home/2340-issuetrak-release-notes |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-12123 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-12123 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-12-04 13:21:28 | Added to TrackCVE |