CVE-2024-29839
CVSS V2 None
CVSS V3 None
Description
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user
Overview
- CVE ID
- CVE-2024-29839
- Assigner
- directcyber
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-04-14T23:48:00.923Z
- Last Modified Date
- 2024-06-06T15:47:48.124Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://directcyber.com.au/sa/CVE-2024-29836-to-29844-evolution-controller-multiple-vulnerabilities.html |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-29839 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-29839 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 02:33:30 | Added to TrackCVE |