CVE-2024-51556

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to sensitive information belonging to other users.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:63moons:aero:*:*:*:*:*:*:*:*
cpe:2.3:a:63moons:wave_2.0:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-11-04 13:17

Updated : 2024-11-22 12:15


NVD link : CVE-2024-51556

Mitre link : CVE-2024-51556

CVE.ORG link : CVE-2024-51556


JSON object : View

Products Affected

63moons

  • wave_2.0
  • aero
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm