← Back

CVE-2024-8780

nvd nist
Published: Sep 16, 2024Modified: Sep 20, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: twcert@cert.org.tw (Secondary)

Description

OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote attackers with regular privileges to obtain accounts and password hashes of other users.

Affected (1)

Products: Syscomgo: Omflow
1 product
Omflow
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.2.1.3

References (2)

Source: twcert@cert.org.tw
Third Party Advisory
Source: twcert@cert.org.tw
Third Party Advisory

Timeline

No history available yet.