Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.
References
Configurations
No configuration.
History
21 Nov 2024, 09:06
Type | Values Removed | Values Added |
---|---|---|
References | () http://financials.com - | |
References | () http://unit4.com - | |
References | () https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html - | |
References | () https://www.unit4.com/ - | |
References | () https://www.unit4.com/products/financial-management-software - |
01 Aug 2024, 13:49
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
CWE | CWE-287 |
25 Apr 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
01 Apr 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request. |
20 Mar 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-20 15:15
Updated : 2024-11-21 09:06
NVD link : CVE-2024-28735
Mitre link : CVE-2024-28735
CVE.ORG link : CVE-2024-28735
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication