
CVE-2024-48955_Overview
Netadmin 4 IAM with access control flaws.
Affected version: V4.030319
NetAdmin system returns data with functionalities in the endpoint that "builds" the functionality menus; the response of this call is not encrypted, and as the system does not validate session authorization, an attacker can copy the content from a higher-privileged user's browser, gaining access to the functionalities of the user whose code was copied.
Broken Access Control
Base Score: 7.6
Vectors: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
An authenticated attacker can alter the response of the call that the system makes to render the user's screen, thus gaining access to administrative functionalities.
Fix Status: [Under Approval]
Mitigation Instructions:
References: