CVE-2024-6424

Publication date

2024-07-01 12:54:20

Family

INCIBE

State

PUBLISHED

Description

External server-side request vulnerability in MESbook 20221021.03 version, which could allow a remote, unauthenticated attacker to exploit the endpoint "/api/Proxy/Post?userName=&password=&uri=