CVE-2024-45877
Last modified
CVE-2024-45877 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.aspx. This allows a low privileged user to access all modules in the web portal, view and manipulate information and permissions of other users, lock other user or unlock the own account, change the password of other users, create new users or delete existing users and view, manipulate and delete reference data.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.aspx. This allows a low privileged user to access all modules in the web portal, view and manipulate information and permissions of other users, lock other user or unlock the own account, change the password of other users, create new users or delete existing users and view, manipulate and delete reference data.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-45877?
How severe is CVE-2024-45877?
How do I fix CVE-2024-45877?
Are you affected by CVE-2024-45877?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
