Description
An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.
INFO
Published Date :
2024-12-12T13:24:16.685Z
Last Modified :
2025-11-03T21:54:29.638Z
Source :
SEC-VLab
AFFECTED PRODUCTS
The following products are affected by CVE-2024-28144 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-28144.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact