HIGH🇵🇱 Wersja polska

CVE-2024-47653

CVSS 7.1v4.0pub. 2024-10-04upd. 2024-10-16

This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request body leading to unauthorized modification of requests belonging to the other users.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Shilpisoft Client Dashboard

    APP
    Shilpisoft
    < 9.7.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-47656CRITICAL9.3PL ✓same product

Brak ograniczeń prób logowania w Shilpi Client Dashboard (brute force)

CVE-2024-47652HIGH7.6same product

This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechan...

CVE-2024-47654HIGH7.1same product

This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for O...

CVE-2024-47655HIGH8.6same product

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded ot...

CVE-2024-47657HIGH7.1same vendor

This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoin...