CVE-2024-55585

In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated by /api/v1/users/resetpassword.
CVSS

No CVSS.

Configurations

No configuration.

History

13 Jun 2025, 08:15

Type Values Removed Values Added
References
  • () https://www.mops.eu -
Summary
  • (es) En moPS App hasta la versión 1.8.618, todos los usuarios pueden acceder a los endpoints de la API administrativa sin autenticación adicional, lo que da como resultado un acceso de lectura y escritura sin restricciones, como lo demuestra /api/v1/users/resetpassword.

07 Jun 2025, 20:15

Type Values Removed Values Added
Summary (en) In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access. (en) In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated by /api/v1/users/resetpassword.

07 Jun 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-07 19:15

Updated : 2025-06-13 08:15


NVD link : CVE-2024-55585

Mitre link : CVE-2024-55585

CVE.ORG link : CVE-2024-55585


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function