MEDIUM🇵🇱 Wersja polska

CVE-2024-50618

CVSS 4.3v3.1pub. 2026-02-11upd. 2026-02-17

A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypass a protection mechanism. When the system is configured to allow login with internal accounts, an attacker can possibly obtain full authentication if the secret in a single-factor authentication scheme gets compromised.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  • Cipplanner Cipace

    APP
    Cipplanner
    < 9.17
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-11598CRITICAL9.8PL ✓same product

CIPAce 9.1 – nieuwierzytelniony upload i RCE przez plik ASHX

CVE-2020-11597CRITICAL9.8PL ✓same product

SQL Injection bez uwierzytelnienia w CIPPlanner CIPAce 9.1

CVE-2020-11586CRITICAL9.8PL ✓same product

XXE w CIPPlanner CIPAce — nieautoryzowany dostęp przez złośliwe DTD

CVE-2024-50617HIGH7.5same product

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow at...

CVE-2024-50619HIGH8.8same product

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attac...