CVE-2024-13040
CVE-2024-13040
Título es
CVE-2024-13040
Mar, 31/12/2024 – 02:15
Tipo
CWE-639
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-13040
Descripción en
The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation.
31/12/2024
31/12/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Gravedad 3.1 (CVSS 3.1 Base Score)
8.80
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
HIGH
Referencias
Enviar en el boletín
Off