CVE Published: 01/07/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: twcert |
Vendor: CHANGING |
Product: Mobile One Time Password Status : PUBLISHED
CVE-2024-3122 Description
CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.
Metrics
CVSS Version: 3.1 |
Base Score: 4.9 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N