Uncontrolled URL Path Vulnerability in RISWEB Allows Browsing of Sensitive Data Without Login
CVE-2024-26263

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
15 February 2024

What is CVE-2024-26263?

The EBM Technologies RISWEB application has a vulnerability that permits unauthorized users to access restricted sections of the application. This flaw arises from inadequate control over specific URL paths, enabling attackers to explore particular pages and extract sensitive information without needing to authenticate. Organizations using this software should assess their security posture and implement necessary measures to prevent data breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

RISWEB 1.*

RISWEB 2.*

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.