CVE-2024-12123

MEDIUM

Issuetrak 17.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user.  When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy.  The ticket requester can be changed from the original requester to another user in the same application, which the application then accepts.

Scores

CVSS v4 5.3
EPSS 0.0013
EPSS Percentile 31.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-472 CWE-837
Status published
Products (1)
Issuetrak/Issuetrak Issuetrak 17.1
Published Dec 04, 2024
Tracked Since Feb 18, 2026