CVE-2024-50617
Last modified
CVE-2024-50617 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file path in the URL query string to retrieve the files. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file path in the URL query string to retrieve the files. (Retrieval is not intended without correct data access configured for documents.)
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cipplanner | Cipace | < 9.17 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-50617?
How severe is CVE-2024-50617?
How do I fix CVE-2024-50617?
Are you affected by CVE-2024-50617?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
