CVE-2024-31845

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.
References
Link Resource
https://www.gruppotim.it/it/footer/red-team.html Exploit Third Party Advisory
https://www.gruppotim.it/it/footer/red-team.html Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:italtel:embrace:1.6.4:*:*:*:*:*:*:*

History

21 May 2025, 18:18

Type Values Removed Values Added
CPE cpe:2.3:a:italtel:embrace:1.6.4:*:*:*:*:*:*:*
References () https://www.gruppotim.it/it/footer/red-team.html - () https://www.gruppotim.it/it/footer/red-team.html - Exploit, Third Party Advisory
First Time Italtel
Italtel embrace

Information

Published : 2024-05-21 16:15

Updated : 2025-05-21 18:18


NVD link : CVE-2024-31845

Mitre link : CVE-2024-31845

CVE.ORG link : CVE-2024-31845


JSON object : View

Products Affected

italtel

  • embrace
CWE
CWE-117

Improper Output Neutralization for Logs