CVE-2024-45877
Last modified
CVE-2024-45877 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.aspx. This allows a low privileged user to access all modules in the web portal, view and manipulate information and permissions of other users, lock other user or unlock the own account, change the password of other users, create new users or delete existing users and view, manipulate and delete reference data.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.aspx. This allows a low privileged user to access all modules in the web portal, view and manipulate information and permissions of other users, lock other user or unlock the own account, change the password of other users, create new users or delete existing users and view, manipulate and delete reference data.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-45877?
How severe is CVE-2024-45877?
How do I fix CVE-2024-45877?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45871Bandisoft BandiView 7.05 is Incorrect Access Control via sub…6.3
- CVE-2024-45872Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow vi…6.3
- CVE-2024-45873A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 all…9.8
- CVE-2024-45874A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows…9.8
- CVE-2024-45875The create user function in baltic-it TOPqw Webportal 1.35.2…5.4
- CVE-2024-45876The login form of baltic-it TOPqw Webportal v1.35.283.2 (fix…6.5
- CVE-2024-45878The "Stammdaten" menu of baltic-it TOPqw Webportal v1.35.283…5.4
- CVE-2024-45879The file upload function in the "QWKalkulation" tool of balt…5.4
- CVE-2024-4588A vulnerability was found in DedeCMS 5.7. It has been classi…4.3
- CVE-2024-45880A command injection vulnerability exists in Motorola CX2L ro…8
- CVE-2024-45882DrayTek Vigor3900 1.5.1.3 contains a command injection vulne…8
- CVE-2024-45884DrayTek Vigor3900 1.5.1.3 contains a post-authentication com…8
Are you affected by CVE-2024-45877?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
