CVE-2024-29837
—CVSS 3.1
8.8 high
EPSS
<1%p42
Published
()
Modified
Description
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.
- Vendors
- cs-technologies
- Products
- evolution
- Weakness
- CWE-284, CWE-1390, CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.