CVE-2024-57190

Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.
Configurations

No configuration.

History

12 Jun 2025, 16:06

Type Values Removed Values Added
Summary
  • (es) Erxes &lt;1.6.1 es vulnerable a un control de acceso incorrecto. Un atacante puede eludir la autenticación proporcionando un encabezado HTTP "Usuario" que contenga cualquier usuario, lo que le permite comunicarse con cualquier endpoint GraphQL.

10 Jun 2025, 20:15

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

10 Jun 2025, 17:20

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-10 17:20

Updated : 2025-06-12 16:06


NVD link : CVE-2024-57190

Mitre link : CVE-2024-57190

CVE.ORG link : CVE-2024-57190


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control