2024-10-04 14:03:27 +00:00
{
"id" : "CVE-2024-47653" ,
"sourceIdentifier" : "vdisclose@cert-in.org.in" ,
"published" : "2024-10-04T13:15:11.563" ,
2024-10-16 16:03:25 +00:00
"lastModified" : "2024-10-16T15:13:52.280" ,
"vulnStatus" : "Analyzed" ,
2024-10-04 14:03:27 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request body leading to unauthorized modification of requests belonging to the other users."
2024-10-13 02:03:17 +00:00
} ,
{
"lang" : "es" ,
"value" : "Esta vulnerabilidad existe en Shilpi Client Dashboard debido a la falta de autorizaci\u00f3n para solicitudes de modificaci\u00f3n y cancelaci\u00f3n a trav\u00e9s de determinados endpoints de API. Un atacante remoto autenticado podr\u00eda aprovechar esta vulnerabilidad al realizar o cancelar solicitudes a trav\u00e9s del cuerpo de la solicitud de API, lo que provocar\u00eda una modificaci\u00f3n no autorizada de las solicitudes pertenecientes a otros usuarios."
2024-10-04 14:03:27 +00:00
}
] ,
"metrics" : {
"cvssMetricV40" : [
{
"source" : "vdisclose@cert-in.org.in" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "4.0" ,
"vectorString" : "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 7.1 ,
"baseSeverity" : "HIGH" ,
2024-10-04 14:03:27 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"attackRequirements" : "NONE" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
2025-03-02 03:03:52 +00:00
"vulnConfidentialityImpact" : "NONE" ,
"vulnIntegrityImpact" : "HIGH" ,
"vulnAvailabilityImpact" : "NONE" ,
"subConfidentialityImpact" : "NONE" ,
"subIntegrityImpact" : "LOW" ,
"subAvailabilityImpact" : "NONE" ,
2024-10-04 14:03:27 +00:00
"exploitMaturity" : "NOT_DEFINED" ,
2025-03-02 03:03:52 +00:00
"confidentialityRequirement" : "NOT_DEFINED" ,
"integrityRequirement" : "NOT_DEFINED" ,
"availabilityRequirement" : "NOT_DEFINED" ,
2024-10-04 14:03:27 +00:00
"modifiedAttackVector" : "NOT_DEFINED" ,
"modifiedAttackComplexity" : "NOT_DEFINED" ,
"modifiedAttackRequirements" : "NOT_DEFINED" ,
"modifiedPrivilegesRequired" : "NOT_DEFINED" ,
"modifiedUserInteraction" : "NOT_DEFINED" ,
2025-03-02 03:03:52 +00:00
"modifiedVulnConfidentialityImpact" : "NOT_DEFINED" ,
"modifiedVulnIntegrityImpact" : "NOT_DEFINED" ,
"modifiedVulnAvailabilityImpact" : "NOT_DEFINED" ,
"modifiedSubConfidentialityImpact" : "NOT_DEFINED" ,
"modifiedSubIntegrityImpact" : "NOT_DEFINED" ,
"modifiedSubAvailabilityImpact" : "NOT_DEFINED" ,
"Safety" : "NOT_DEFINED" ,
"Automatable" : "NOT_DEFINED" ,
"Recovery" : "NOT_DEFINED" ,
2024-10-04 14:03:27 +00:00
"valueDensity" : "NOT_DEFINED" ,
"vulnerabilityResponseEffort" : "NOT_DEFINED" ,
2024-12-08 03:06:42 +00:00
"providerUrgency" : "NOT_DEFINED"
2024-10-04 14:03:27 +00:00
}
}
2024-10-16 16:03:25 +00:00
] ,
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM" ,
2024-10-16 16:03:25 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2024-10-16 16:03:25 +00:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 3.6
}
2024-10-04 14:03:27 +00:00
]
} ,
"weaknesses" : [
{
2024-12-08 03:06:42 +00:00
"source" : "vdisclose@cert-in.org.in" ,
"type" : "Secondary" ,
2024-10-16 16:03:25 +00:00
"description" : [
{
"lang" : "en" ,
2024-12-08 03:06:42 +00:00
"value" : "CWE-266"
2024-10-16 16:03:25 +00:00
}
]
} ,
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2024-10-04 14:03:27 +00:00
"description" : [
{
"lang" : "en" ,
2024-12-08 03:06:42 +00:00
"value" : "NVD-CWE-Other"
2024-10-04 14:03:27 +00:00
}
]
}
] ,
2024-10-16 16:03:25 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "9.7.0" ,
"matchCriteriaId" : "BC172203-D79B-43A2-A195-9C370BDEA79F"
}
]
}
]
}
] ,
2024-10-04 14:03:27 +00:00
"references" : [
{
"url" : "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313" ,
2024-10-16 16:03:25 +00:00
"source" : "vdisclose@cert-in.org.in" ,
"tags" : [
"Third Party Advisory"
]
2024-10-04 14:03:27 +00:00
}
]
}