CVE-2024-45588
CVE-2024-45588
Título es
CVE-2024-45588
Mar, 03/09/2024 – 11:15
Tipo
CWE-863
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-45588
Descripción en
This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Preference module of the application. An authenticated remote attacker could exploit this vulnerability by manipulating parameters through HTTP request which could lead to unauthorized access and modification of sensitive information belonging to other users.
03/09/2024
03/09/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Enviar en el boletín
Off