CVE-2024-36523

MEDIUM

Wvp GB28181 Pro 2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

An access control issue in Wvp GB28181 Pro 2.0 allows users to continue to access information in the application after deleting their own or administrator accounts. This is provided that the users do not log out of their deleted accounts.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0034
EPSS Percentile 25.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (1)
wvp-pro/gb28181 2.0
Published Jun 12, 2024
Tracked Since Feb 18, 2026