Security Advisory

CVE-2024-47653

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-10-04 12:15:44
Last updated 2024-10-04 14:11:03
Assigner CERT-In
CVSS score 7.1
State PUBLISHED

Description

This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request body leading to unauthorized modification of requests belonging to the other users.