CVE-2024-31845

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/05/2024
Last modified:
21/05/2025

Description

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:italtel:embrace:1.6.4:*:*:*:*:*:*:*