CVE-2024-55470

Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or access restricted data without proper authorization. The lack of server-side validation exacerbates the issue, as the application relies on client-side information for authentication.
Configurations

No configuration.

History

20 Dec 2024, 18:15

Type Values Removed Values Added
CWE CWE-290
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

20 Dec 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-20 16:15

Updated : 2024-12-20 18:15


NVD link : CVE-2024-55470

Mitre link : CVE-2024-55470

CVE.ORG link : CVE-2024-55470


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing