{ "id": "CVE-2024-37767", "sourceIdentifier": "cve@mitre.org", "published": "2024-07-05T17:15:11.533", "lastModified": "2024-07-08T15:49:22.437", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request." }, { "lang": "es", "value": " Los permisos inseguros en el componente /api/admin/user de 14Finger v1.1 permiten a los atacantes acceder a toda la informaci\u00f3n del usuario a trav\u00e9s de una solicitud GET manipulada." } ], "metrics": {}, "references": [ { "url": "https://github.com/b1ackc4t/14Finger/issues/12", "source": "cve@mitre.org" } ] }