CVE-2024-9513

LOW

Netadmin Iam < 3.5 - Information Disclosure

Title source: rule
STIX 2.1

Description

A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /controller/api/Answer/ReturnUserQuestionsFilled of the component HTTP POST Request Handler. The manipulation of the argument username leads to information exposure through discrepancy. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure is planning to release a fix in mid-October 2024.

Exploits (1)

nomisec WORKING POC 1 stars
by ELIZEUOPAIN · poc
https://github.com/ELIZEUOPAIN/Exploit-CVE-2024-9513-NetAdmin-IAM-Allows-User-Enumeration-In-Active-Directory

Scores

CVSS v3 3.7
EPSS 0.1361
EPSS Percentile 94.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-203
Status published
Products (1)
netadmin/netadmin_iam < 3.5
Published Oct 04, 2024
Tracked Since Feb 18, 2026