CVE-2024-57190

Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.
Configurations

Configuration 1 (hide)

cpe:2.3:a:erxes:erxes:*:*:*:*:*:*:*:*

History

20 Jun 2025, 13:07

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-10 17:20

Updated : 2025-06-20 13:07


NVD link : CVE-2024-57190

Mitre link : CVE-2024-57190

CVE.ORG link : CVE-2024-57190


JSON object : View

Products Affected

erxes

  • erxes
CWE
CWE-284

Improper Access Control