CVE-2024-49373

MEDIUM

No Fuss Computing Centurion ERP <1.2.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations they are not apart of. Version 1.2.1 fixes the problem.

Scores

CVSS v3 4.1
EPSS 0.0057
EPSS Percentile 68.6%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-653
Status published
Products (1)
nofusscomputing/centurion_erp < 1.2.1
Published Oct 22, 2024
Tracked Since Feb 18, 2026