CVE-2024-31845

MEDIUM

Italtel Embrace 1.6.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.

Scores

CVSS v3 5.3
EPSS 0.0014
EPSS Percentile 33.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-117
Status published
Products (1)
italtel/embrace 1.6.4
Published May 21, 2024
Tracked Since Feb 18, 2026