CVE Published: Invalid date format |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: mitre |
Vendor: n/a |
Product: n/a Status : PUBLISHED
CVE-2024-31845 Description
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.