CVE-2024-0949

Improper Access Control, Missing Authorization, Incorrect Authorization, Incorrect Permission Assignment for Critical Resource, Missing Authentication, Weak Authentication, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Talya Informatics Elektraweb allows Exploiting Incorrectly Configured Access Control Security Levels, Manipulating Web Input to File System Calls, Embedding Scripts within Scripts, Malicious Logic Insertion, Modification of Windows Service Configuration, Malicious Root Certificate, Intent Spoof, WebView Exposure, Data Injected During Configuration, Incomplete Data Deletion in a Multi-Tenant Environment, Install New Service, Modify Existing Service, Install Rootkit, Replace File Extension Handlers, Replace Trusted Executable, Modify Shared File, Add Malicious File to Shared Webroot, Run Software at Logon, Disable Security Software.This issue affects Elektraweb: before v17.0.68.
Configurations

No configuration.

History

No history.

Information

Published : 2024-06-27 10:15

Updated : 2024-06-27 12:47


NVD link : CVE-2024-0949

Mitre link : CVE-2024-0949

CVE.ORG link : CVE-2024-0949


JSON object : View

Products Affected

No product.

CWE
CWE-1390

Weak Authentication

CWE-284

Improper Access Control

CWE-306

Missing Authentication for Critical Function

CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-862

Missing Authorization

CWE-863

Incorrect Authorization

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints