CVE-2024-8601

This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to unauthorized access to sensitive information belonging to other users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:techexcel:back_office_software:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-09 10:15

Updated : 2024-09-17 17:54


NVD link : CVE-2024-8601

Mitre link : CVE-2024-8601

CVE.ORG link : CVE-2024-8601


JSON object : View

Products Affected

techexcel

  • back_office_software
CWE
CWE-639

Authorization Bypass Through User-Controlled Key

CWE-863

Incorrect Authorization