ZeroHour

CVE-2024-9984

CVSS 3.1
9.8 critical
EPSS
<1%p45
Published
()
Modified
Description

Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.

Vendors
ragic
Products
enterprise cloud database
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.