Description

An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.

INFO

Published Date :

2024-12-12T13:24:16.685Z

Last Modified :

2025-11-03T21:54:29.638Z

Source :

SEC-VLab
AFFECTED PRODUCTS

The following products are affected by CVE-2024-28144 vulnerability.

No data.

REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-28144.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact