CVE-2024-47653

MEDIUM

Shilpi Client Dashboard - Privilege Escalation

Title source: llm
STIX 2.1

Description

This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request body leading to unauthorized modification of requests belonging to the other users.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0033
EPSS Percentile 24.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-266
Status published
Products (1)
shilpisoft/client_dashboard < 9.7.0
Published Oct 04, 2024
Tracked Since Feb 18, 2026