CVE-2024-0949
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
27/06/2024
Last modified:
14/10/2025
Description
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass.This issue affects Elektraweb: before v17.0.68.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



