Reedos aiM-Star Vulnerability: Sensitive Information at Risk
CVE-2024-45787

6.5MEDIUM

What is CVE-2024-45787?

The vulnerability in Reedos aiM-Star version 2.0.1 presents a significant risk due to the transmission of sensitive information in plaintext across certain API endpoints. An authenticated remote attacker may exploit this weakness by manipulating parameters within the API request URL, facilitating the interception of API responses. This manipulation can potentially expose sensitive information pertaining to other users, thereby compromising their data security and privacy.

Affected Version(s)

Mutual Fund Distribution Product (aiM-Star) 2.0.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Mohit Gadiya.
.