CVE-2024-38742

MEDIUM

MBE eShip <= 2.1.2 - Exposure of Sensitive Information via Improper Access Control

Title source: llm
STIX 2.1

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MBE Worldwide S.P.A. MBE eShip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MBE eShip: from n/a through 2.1.2.

Scores

CVSS v3 5.3
EPSS 0.0036
EPSS Percentile 28.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
MBE Worldwide S.p.A./MBE eShip < 2.1.2
Published Aug 13, 2024
Tracked Since Feb 18, 2026