A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user.
When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy. The ticket requester can be changed from the original requester to another user in the same application,
which the application then accepts.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Dec 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 04 Dec 2024 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy. The ticket requester can be changed from the original requester to another user in the same application, which the application then accepts. | |
Title | Unauthorized Modification of Ticket Requester | |
Weaknesses | CWE-472 CWE-837 |
|
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: Gridware
Published: 2024-12-04T03:26:00.918Z
Updated: 2024-12-04T14:09:11.911Z
Reserved: 2024-12-03T23:13:54.977Z
Link: CVE-2024-12123
Vulnrichment
Updated: 2024-12-04T14:05:31.553Z
NVD
Status : Received
Published: 2024-12-04T04:15:04.430
Modified: 2024-12-04T04:15:04.430
Link: CVE-2024-12123
Redhat
No data.