Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a vulnerability in access control mechanisms by removing authentication-related HTTP headers, such as the Cookie header, in the request. This bypasses the authentication process and grants attackers access to sensitive image files without proper login credentials.
References
Configurations
No configuration.
History
11 Feb 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
10 Feb 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.4 |
CWE | CWE-284 |
07 Feb 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-07 16:15
Updated : 2025-02-11 16:15
NVD link : CVE-2024-57249
Mitre link : CVE-2024-57249
CVE.ORG link : CVE-2024-57249
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control