VulnerabilityAnalyzed
CVE-2024-56114
Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks.
MEDIUM 6.5EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- henkel/canlineapp
- Source
- cve@mitre.org
References
- https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2024-56114Exploit, Third Party Advisory
- https://www.e-connectsolutions.comNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.