CVE-2024-47651

This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple “userid” parameters in the API request body leading to unauthorized access of sensitive information belonging to other users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:shilpi:client_dashboard:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-04 12:15

Updated : 2024-10-10 21:01


NVD link : CVE-2024-47651

Mitre link : CVE-2024-47651

CVE.ORG link : CVE-2024-47651


JSON object : View

Products Affected

shilpi

  • client_dashboard
CWE
CWE-235

Improper Handling of Extra Parameters

NVD-CWE-Other