Remote User Can Obtain Purchased Ticket Download URL
CVE-2024-4537

7.5HIGH

Key Information:

Vendor

Impronta

Vendor
CVE Published:
7 May 2024

What is CVE-2024-4537?

The Janto Ticketing Software presents a significant security vulnerability characterized by an Insecure Direct Object Reference (IDOR). This flaw exists in version 4.3r10 and enables a remote attacker to retrieve the download URL of another user's purchased ticket. Such exposure can lead to unauthorized access to sensitive user data, potentially compromising the user experience and integrity of the ticketing process. Organizations utilizing this software should prioritize remediation of this vulnerability to safeguard against unauthorized data access.

Affected Version(s)

Janto Ticketing Software 4.3r10.cks

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alejandro Amorín Niño
.