CVE-2024-45786

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to gain unauthorized access to sensitive information belonging to other users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:reedos:aim-star:2.0.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-11 12:15

Updated : 2024-09-18 20:12


NVD link : CVE-2024-45786

Mitre link : CVE-2024-45786

CVE.ORG link : CVE-2024-45786


JSON object : View

Products Affected

reedos

  • aim-star
CWE
CWE-639

Authorization Bypass Through User-Controlled Key