CVE-2024-47089

MEDIUM

Apex Softcell LD Geo - Privilege Escalation

Title source: llm
STIX 2.1

Description

This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating the transaction token ID in the API request leading to unauthorized access and modification of transactions belonging to other users.

Scores

CVSS v3 6.5
EPSS 0.0009
EPSS Percentile 25.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-354
Status published
Products (2)
apexsoftcell/ld_dp_back_office < 24.8.21.1
apexsoftcell/ld_geo < 4.0.0.7
Published Sep 19, 2024
Tracked Since Feb 18, 2026