Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-48955_Overview — CVE-2024-48955_Overview | Kitploit
Tools/GitHubGitHub/brotherofjhonny/cve-2024-48955_overview
Authentication & AuthorizationVulnerability AnalysisExploitationWeb SecurityPenetration TestingMisconfiguration
GitHubbrotherofjhonny/cve-2024-48955_overview

CVE-2024-48955_Overview

CVE-2024-48955_Overview

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
41 year agoNot yet reviewed

CVE-2024-48955_Overview

Description:

Netadmin 4 IAM with access control flaws.

Affected version: V4.030319

NetAdmin system returns data with functionalities in the endpoint that "builds" the functionality menus; the response of this call is not encrypted, and as the system does not validate session authorization, an attacker can copy the content from a higher-privileged user's browser, gaining access to the functionalities of the user whose code was copied.

Vulnerability Type

Broken Access Control

CVSS Score and Attack Vectors

Base Score: 7.6
Vectors: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Validating the vulnerability:

An authenticated attacker can alter the response of the call that the system makes to render the user's screen, thus gaining access to administrative functionalities.

Solution

Fix Status: [Under Approval]

Mitigation Instructions:

  • Request a version update from the vendor

References:

  • CWE-863: Incorrect Authorization
  • CWE-862: Missing Authorization
  • CWE-284: Improper Access Control
  • CWE-639: Authorization Bypass Through User-Controlled Key
Download Tool