CVE-2024-50650

HIGH

Timgreen Python Book - Incorrect Authorization

Title source: rule
STIX 2.1

Description

python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

Scores

CVSS v3 7.5
EPSS 0.0047
EPSS Percentile 64.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
timgreen/python_book 1.0
Published Nov 15, 2024
Tracked Since Feb 18, 2026