← Back

CVE-2024-3122

nvd nist
Published: Jul 1, 2024Modified: Jun 17, 2026Deferred

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: twcert@cert.org.tw (Secondary)

Description

CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.

References (4)

Timeline

No history available yet.