CVE-2024-50651

MEDIUM

java_shop 1.0 - Unauthenticated Incorrect Access Control via ID Parameter

Title source: llm
STIX 2.1

Description

java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

Scores

CVSS v3 6.5
EPSS 0.0049
EPSS Percentile 38.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
geeeeeeeek/java_shop 1.0
Published Nov 15, 2024
Tracked Since Feb 18, 2026