CVE-2024-7266

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
07/08/2024
Last modified:
17/03/2025

Description

Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nask:ezd_rp:*:*:*:*:*:*:*:* 15 (including) 15.84 (excluding)
cpe:2.3:a:nask:ezd_rp:*:*:*:*:*:*:*:* 16 (including) 16.15 (excluding)
cpe:2.3:a:nask:ezd_rp:*:*:*:*:*:*:*:* 17 (including) 17.2 (excluding)