CVE-2024-57190
10.06.2025, 17:20
Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.Enginsight
Vendor | Product | Version |
---|---|---|
erxes | erxes | 𝑥 < 1.6.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration