8.1

CVE-2024-28735

Exploit
Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Unit4Financials By Coda Version < 2023q4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.73% 0.494
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://www.unit4.com/
Product
https://www.unit4.com/products/financial-management-software
Product
http://financials.com
Broken Link
http://unit4.com
Product
https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html
Third Party Advisory
Exploit