This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicious activities on other user accounts.
References
Link | Resource |
---|---|
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0332 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-11-04 13:17
Updated : 2024-11-22 12:15
NVD link : CVE-2024-51559
Mitre link : CVE-2024-51559
CVE.ORG link : CVE-2024-51559
JSON object : View
Products Affected
63moons
- wave_2.0
- aero
CWE
CWE-639
Authorization Bypass Through User-Controlled Key