← Retour aux CVEs
CVE-2024-28143
HIGH8.4
Description
The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing the old password, e.g. by exploiting a CSRF issue.
Details CVE
Score CVSS v3.18.4
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie12/12/2024
Derniere modification11/3/2025
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-620
References
https://r.sec-consult.com/imageaccess(551230f0-3615-47bd-b7cc-93e92e730bbf)
https://www.imageaccess.de/?page=SupportPortal&lang=en(551230f0-3615-47bd-b7cc-93e92e730bbf)
http://seclists.org/fulldisclosure/2024/Dec/2(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.