CVE-2024-9984

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
15/10/2024
Last modified:
16/10/2024

Description

Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ragic:enterprise_cloud_database:*:*:*:*:*:*:*:* 2024-08-08 (excluding)