CVE-2024-45587
Last modified
CVE-2024-45587 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Transaction module of vulnerable application. An authenticated remote attacker could exploit this vulnerability by manipulating parameters through HTTP request which could lead to compromise of other user accounts.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Transaction module of vulnerable application. An authenticated remote attacker could exploit this vulnerability by manipulating parameters through HTTP request which could lead to compromise of other user accounts.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Symphonyfintech | Xts Mobile Trader | 2.0.0.1 | P160 |
| Symphonyfintech | Xts Web Trader | 2.0.0.1 | P160 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-45587?
How severe is CVE-2024-45587?
How do I fix CVE-2024-45587?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45580Memory corruption while handling multuple IOCTL calls from u…7.8
- CVE-2024-45581Memory corruption while sound model registration for voice a…7.8
- CVE-2024-45582Memory corruption while validating number of devices in Came…7.8
- CVE-2024-45583Memory corruption while handling multiple IOCTL calls from u…7.8
- CVE-2024-45584Memory corruption can occur when a compat IOCTL call is foll…7.8
- CVE-2024-45586This vulnerability exists due to improper access controls on…8.8
- CVE-2024-45588This vulnerability exists in Symphony XTS Web Trading platfo…8.1
- CVE-2024-45589RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08…5.9
- CVE-2024-4559Heap buffer overflow in WebAudio in Google Chrome prior to 1…6.5
- CVE-2024-45590body-parser is Node.js body parsing middleware. body-parser …7.5
- CVE-2024-45591XWiki Platform is a generic wiki platform. The REST API expo…5.3
- CVE-2024-45592auditor-bundle, formerly known as DoctrineAuditBundle, integ…6.1
Are you affected by CVE-2024-45587?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
