WeGIA 3.2.0 before 3998672 does not verify permission to change a password.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.wegia.org | product |
https://github.com/nmmorette/vulnerability-research/tree/main/CVE-2024-53473 | third party advisory exploit |
https://github.com/nilsonLazarin/WeGIA/commit/3998672f1b86db58eab2808a640903d73b37bd2d | patch |
https://github.com/nilsonLazarin/WeGIA/issues/791 | vendor advisory exploit |
https://github.com/nmmorette/vulnerability-research/blob/main/CVE-2024-53473/README.md | third party advisory exploit |