8.1
CVE-2024-28735
- EPSS 0.07%
- Veröffentlicht 20.03.2024 15:15:07
- Zuletzt bearbeitet 17.06.2025 13:25:30
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Unit4 ≫ Financials By Coda Version < 2023q4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.212 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.