CVE-2024-11318 Information

Description

An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet affecting version 2.3.1. This vulnerability could allow a remote attacker to obtain the session of an unauthenticated user by brute-force attacking the session identifier on the /cgi-bin/ocap/\ endpoint.

Reference

https://www.incibe.es/en/incibe-cert/notices/aviso/idor-vulnerability-absysnet

Share on: