CVE-2024-46097
Last modified
CVE-2024-46097 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another ID. The application does not carry out a check on the user's permissions maing it possible to recover the IDs of all the TestPlans (even the administrative ones) and modify them even with minimal privileges.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Testlink | Testlink | 1.9.20 |
References
- https://github.com/Alkatraz97/CVEs/blob/main/CVE-2024-46097.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-46097?
How severe is CVE-2024-46097?
How do I fix CVE-2024-46097?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-46084Scriptcase 9.10.023 and before is vulnerable to Remote Code …8
- CVE-2024-46085FrogCMS V0.9.5 was discovered to contain a Cross-Site Reques…8.8
- CVE-2024-46086FrogCMS V0.9.5 was discovered to contain a Cross-Site Reques…8.8
- CVE-2024-46088An arbitrary file upload vulnerability in the ProductAction.…9.8
- CVE-2024-4608974cms <=3.33 is vulnerable to remote code execution (RCE) in…6.3
- CVE-2024-4609A vulnerability exists in the Rockwell Automation FactoryTal…9.8
- CVE-2024-4610Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel D…7.8
- CVE-2024-46101GDidees CMS <= v3.9.1 has a file upload vulnerability.9.8
- CVE-2024-46103SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.ph…9.8
- CVE-2024-4611The AppPresser plugin for WordPress is vulnerable to imprope…8.1
- CVE-2024-4612An issue has been discovered in GitLab EE affecting all vers…6.1
- CVE-2024-4614Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
Are you affected by CVE-2024-46097?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
