Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to vis_client_id.
References
Configurations
No configuration.
History
16 Apr 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-16 23:16
Updated : 2026-04-17 15:38
NVD link : CVE-2024-58343
Mitre link : CVE-2024-58343
CVE.ORG link : CVE-2024-58343
JSON object : View
Products Affected
No product.
CWE
CWE-425
Direct Request ('Forced Browsing')
