HIGH🇵🇱 Wersja polska

CVE-2024-50617

CVSS 7.5v3.1pub. 2026-02-11upd. 2026-02-13

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file path in the URL query string to retrieve the files. (Retrieval is not intended without correct data access configured for documents.)

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Cipplanner Cipace

    APP
    Cipplanner
    < 9.17
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-11598CRITICAL9.8PL ✓same product

CIPAce 9.1 – nieuwierzytelniony upload i RCE przez plik ASHX

CVE-2020-11597CRITICAL9.8PL ✓same product

SQL Injection bez uwierzytelnienia w CIPPlanner CIPAce 9.1

CVE-2020-11586CRITICAL9.8PL ✓same product

XXE w CIPPlanner CIPAce — nieautoryzowany dostęp przez złośliwe DTD

CVE-2024-50619HIGH8.8same product

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attac...

CVE-2024-50620HIGH8.8same product

Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document man...