CVE-2024-31845 Information
May 23, 2024
cve
Description
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker so that every action he performs is attributed to a different user. This can be exploited without authentication.
Reference
https://www.gruppotim.it/it/footer/red-team.html
Share on: