CVE Published: 18/01/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: INCIBE |
Vendor: IDMSistemas |
Product: Sinergia, Sinergia 2.0, and Sinergia Corporativo Status : PUBLISHED
CVE-2024-0580 Description
Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerability allows an attacker to extract sensitive information from the API by making a request to the parameter \'/qsige.locator/quotePrevious/centers/X\', where X supports values 1,2,3, etc.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N