Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.
References
Configurations
No configuration.
History
16 Jan 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-863 | |
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
09 Jan 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-09 20:15
Updated : 2025-01-16 19:15
NVD link : CVE-2024-56114
Mitre link : CVE-2024-56114
CVE.ORG link : CVE-2024-56114
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization