CVE-2024-51559

MEDIUM

Wave 2.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicious activities on other user accounts.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0039
EPSS Percentile 60.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
63moons/aero < 120820241550
63moons/wave_2.0 < 1.1.7
Published Nov 04, 2024
Tracked Since Feb 18, 2026