CVE-2024-51556

MEDIUM

63moons Wave 2.0 < 1.1.7 - Authenticated Sensitive Data Exposure via Insufficient API Response Encryption

Title source: llm
STIX 2.1

Description

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to sensitive information belonging to other users.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0021
EPSS Percentile 11.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-327
Status published
Products (2)
63moons/aero < 120820241550
63moons/wave_2.0 < 1.1.7
Published Nov 04, 2024
Tracked Since Feb 18, 2026