ZeroHour

CVE-2024-56114

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p26
Published
()
Modified
Description

Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.

Vendors
henkel
Products
canlineapp
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.