CVE-2024-50617

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file path in the URL query string to retrieve the files. (Retrieval is not intended without correct data access configured for documents.)
Configurations

Configuration 1 (hide)

cpe:2.3:a:cipplanner:cipace:*:*:*:*:*:*:*:*

History

13 Feb 2026, 21:38

Type Values Removed Values Added
References () https://cipplanner.com/cve-2024-50617-cve-public-notification-of-resolution/ - () https://cipplanner.com/cve-2024-50617-cve-public-notification-of-resolution/ - Vendor Advisory
CPE cpe:2.3:a:cipplanner:cipace:*:*:*:*:*:*:*:*
First Time Cipplanner cipace
Cipplanner

12 Feb 2026, 16:16

Type Values Removed Values Added
CWE CWE-285
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

11 Feb 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 22:15

Updated : 2026-02-13 21:38


NVD link : CVE-2024-50617

Mitre link : CVE-2024-50617

CVE.ORG link : CVE-2024-50617


JSON object : View

Products Affected

cipplanner

  • cipace
CWE
CWE-285

Improper Authorization