CVE-2024-12123

A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user.  When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy.  The ticket requester can be changed from the original requester to another user in the same application, which the application then accepts.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2024-12-04 04:15

Updated : 2024-12-04 04:15


NVD link : CVE-2024-12123

Mitre link : CVE-2024-12123

CVE.ORG link : CVE-2024-12123


JSON object : View

Products Affected

No product.

CWE
CWE-472

External Control of Assumed-Immutable Web Parameter

CWE-837

Improper Enforcement of a Single, Unique Action