Unauthorized Access to Sensitive Information in MBE eShip Due to Inadequate Access Control Lists (ACLs)
CVE-2024-38742
5.3MEDIUM
Key Information
- Vendor
- Mbe Worldwide S.p.a.
- Status
- Mbe Eship
- Vendor
- CVE Published:
- 13 August 2024
Summary
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MBE Worldwide S.P.A. MBE eShip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MBE eShip: from n/a through 2.1.2.
Affected Version(s)
MBE eShip <= 2.1.2
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database
Credit
Joshua Chan (Patchstack Alliance)