CVE-2024-47652 Vulnerability Details

  /     /     /  

CVE-2024-47652 Metadata Quick Info

CVE Published: 04/10/2024 | CVE Updated: 04/10/2024 | CVE Year: 2024
Source: CERT-In | Vendor: Shilpi Computers | Product: Client Dashboard
Status : PUBLISHED

CVE-2024-47652 Description

This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their corresponding mobile number. A remote attacker could exploit this vulnerability by providing mobile number of targeted user, to obtain complete access to the targeted user account.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-308
CWE Name: CWE-308: Use of Single-factor Authentication
Source: Shilpi Computers

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).