CVE-2024-50967
Missing Authorization
Record summary
CVE-2024-50967 has a selected CVSS score of 6.5 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DATAGerryBrowse DATAGerry / DATAGerry | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHub0xByteHunter/CVE-2024-50967Repository PoCby 0xByteHunterStars: 0Not analyzed2 files
Nuclei templates
1ProjectDiscoveryHIGHDATAGERRY - Improper Access Control
The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.
Impact
Attackers can exploit this vulnerability to compromise system security and integrity.
Remediation
Apply the latest security patches and updates to address this vulnerability.
Source: ProjectDiscovery