CVE-2024-31845

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.
Configurations

No configuration.

History

No history.

Information

Published : 2024-05-21 16:15

Updated : 2024-07-03 01:55


NVD link : CVE-2024-31845

Mitre link : CVE-2024-31845

CVE.ORG link : CVE-2024-31845


JSON object : View

Products Affected

No product.

CWE
CWE-117

Improper Output Neutralization for Logs