CVE-2024-50617

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file path in the URL query string to retrieve the files. (Retrieval is not intended without correct data access configured for documents.)
Configurations

Configuration 1 (hide)

cpe:2.3:a:cipplanner:cipace:*:*:*:*:*:*:*:*

History

17 Jun 2026, 08:04

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidades en los componentes manejadores de Descarga de Archivos y Obtener Archivo en CIPPlanner CIPAce anterior a la versión 9.17 permiten a los atacantes descargar archivos no autorizados. Un usuario autenticado puede cambiar fácilmente el parámetro 'file id' o pasar la ruta de archivo física en la cadena de consulta de la URL para recuperar los archivos. (La recuperación no está prevista sin el acceso a datos correcto configurado para los documentos.)

13 Feb 2026, 21:38

Type Values Removed Values Added
References () https://cipplanner.com/cve-2024-50617-cve-public-notification-of-resolution/ - () https://cipplanner.com/cve-2024-50617-cve-public-notification-of-resolution/ - Vendor Advisory
CPE cpe:2.3:a:cipplanner:cipace:*:*:*:*:*:*:*:*
First Time Cipplanner cipace
Cipplanner

12 Feb 2026, 16:16

Type Values Removed Values Added
CWE CWE-285
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

11 Feb 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 22:15

Updated : 2026-06-17 08:04


NVD link : CVE-2024-50617

Mitre link : CVE-2024-50617

CVE.ORG link : CVE-2024-50617


JSON object : View

Products Affected

cipplanner

  • cipace
CWE
CWE-285

Improper Authorization