Description
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.
INFO
Published Date :
2024-05-21T15:33:40.135Z
Last Modified :
2025-02-13T15:47:59.505Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2024-31845 vulnerability.
| Vendors | Products |
|---|---|
| Italtel |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-31845.
| URL | Resource |
|---|---|
| https://www.gruppotim.it/it/footer/red-team.html |
|
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact