CVE-2024-47089 Vulnerability Details

  /     /     /  

CVE-2024-47089 Metadata Quick Info

CVE Published: 19/09/2024 | CVE Updated: 19/09/2024 | CVE Year: 2024
Source: CERT-In | Vendor: Apex Softcell | Product: LD Geo
Status : PUBLISHED

CVE-2024-47089 Description

This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating the transaction token ID in the API request leading to unauthorized access and modification of transactions belonging to other users.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-354
CWE Name: CWE-354: Improper Validation of Integrity Check Value
Source: Apex Softcell

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).