CRITICAL🇵🇱 Wersja polska

CVE-2024-6424

CVSS 9.3v3.1pub. 2024-07-01upd. 2025-10-22

External server-side request vulnerability in MESbook 20221021.03 version, which could allow a remote, unauthenticated attacker to exploit the endpoint "/api/Proxy/Post?userName=&password=&uri=<FILE|INTERNAL URL|IP/HOST" or "/api/Proxy/Get?userName=&password=&uri=<ARCHIVO|URL INTERNA|IP/HOST" to read the source code of web files, read internal files or access network resources.

🤖 AI Analysis
How it works

An attacker sends an HTTP request to unprotected API endpoints: '/api/Proxy/Post?userName=&password=&uri=' or '/api/Proxy/Get?userName=&password=&uri=', providing as the 'uri' parameter a file path, internal URL, or IP address/hostname. The server fulfills the request on behalf of the attacker, allowing reading of web source code, internal system files, and querying of internal network resources. The lack of authentication mechanism on these endpoints makes the attack available to any remote entity without possessing any credentials.

Impact

An attacker can read sensitive files from the server (including web application source code and internal files) and gain access to internal network resources that are not directly accessible from the outside, which may lead to disclosure of sensitive data and further compromise of the infrastructure.

Mitigation & patch

Apply patches available from the vendor according to the references. Additionally, it is recommended to restrict access to API endpoints at the firewall level and enforce authentication on all proxy endpoints.

Who is affected

MESbook version 20221021.03

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
  • Mesbook

    APP
    Mesbook
    20221021.03
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-6425CRITICAL9.1PL ✓same product

MESbook — nieautoryzowana rejestracja kont użytkowników przez API

CVE-2024-6426HIGH8.1same product

Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which could allow a loc...

CVE-2024-6427HIGH7.5same product

Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote atta...