CVE-2024-47657

MEDIUM

Shilpi Net Back Office - Info Disclosure

Title source: llm
STIX 2.1

Description

This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter dfclientid through API request URLs which could lead to unauthorized access to sensitive information belonging to other users.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0013
EPSS Percentile 31.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
shilpisoft/net_back_office < 5.5.002
Published Oct 04, 2024
Tracked Since Feb 18, 2026