CVE-2024-29843
EUVD-2024-2683515.04.2024, 00:15
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated attacker to enumerate all users and their access levelsEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cs-technologies | evolution | 𝑥 ≤ 2.04.560 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration