CVE-2024-42759
MEDIUMDescription
An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ellevo | ellevo |
References
Frequently Asked Questions
What is CVE-2024-42759? +
How severe is CVE-2024-42759? +
What products are affected by CVE-2024-42759? +
How do I check if I'm vulnerable to CVE-2024-42759? +
Related Vulnerabilities
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, …
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to …
Gotham Gaia application was found to be exposing multiple unauthenticated endpoints.
SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /api/mob/instrucao/conta/destinatarios component.
A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in the context of a …