CVE-2024-31845
21.05.2024, 16:15
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.Enginsight
Vendor | Product | Version |
---|---|---|
italtel | embrace | 1.6.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration