CVE-2024-45789
CVE-2024-45789
Título es
CVE-2024-45789
Mié, 11/09/2024 – 12:15
Tipo
CWE-354
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-45789
Descripción en
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process. An authenticated remote attacker could exploit this vulnerability by manipulating parameter in the API request body on the vulnerable application.
Successful exploitation of this vulnerability could allow the attacker to bypass certain constraints in the registration process leading to creation of multiple accounts.
11/09/2024
11/09/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Enviar en el boletín
Off