SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-31845

This parameter can be modified by an attacker, so that every action he performs is attributed to a different user.

MEDIUM 5.3EPSS 0.44%

Does this matter?

Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
0.44% probability · 37th percentile
CISA KEV
Not listed
Weakness
CWE-117
Affected
italtel/embrace
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.