ZeroHour

CVE-2024-29837

CVSS 3.1
8.8 high
EPSS
<1%p42
Published
()
Modified
Description

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.

Vendors
cs-technologies
Products
evolution
Weakness
CWE-284, CWE-1390, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.