CVE-2024-47651CWE-235

Parameter Pollution Vulnerability

High · published October 4, 2024

CVSS v4.0
7.1
EPSS
0%
Percentile
36.2
In the wild
Unconfirmed
What it is

This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple “userid” parameters in the API request body leading to unauthorized access of sensitive information belonging to other users.

The record
Technical detail
CVSS v4.0
7.1 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
EPSS
0.00432 · 36.2th percentile
Weakness
CWE-235 · Improper Handling of Extra Parameters
Published
2024-10-04T12:07Z
EPSS history
Timeline
  • 04 OCT 12:07Z
    Parameter Pollution Vulnerability
    cvelistv5