Remote User Can Obtain Purchased Ticket Download URL
CVE-2024-4537
What is CVE-2024-4537?
The Janto Ticketing Software presents a significant security vulnerability characterized by an Insecure Direct Object Reference (IDOR). This flaw exists in version 4.3r10 and enables a remote attacker to retrieve the download URL of another user's purchased ticket. Such exposure can lead to unauthorized access to sensitive user data, potentially compromising the user experience and integrity of the ticketing process. Organizations utilizing this software should prioritize remediation of this vulnerability to safeguard against unauthorized data access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Janto Ticketing Software 4.3r10.cks
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
