CVE-2024-29836
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 430a6cef-dc26-47e3-9fa8-52fb7f19644e (Secondary)
Description
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user profiles within the application, and gain full access of the site.
Affected (1)
Products: Cs Technologies: Evolution
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.04.560 |
References (2)
Source: 430a6cef-dc26-47e3-9fa8-52fb7f19644e
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.