CVE-2024-2639
Bdtask Wholesale Inventory Management System session fixiation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability was found in Bdtask Wholesale Inventory Management System up to 20240311. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to session fixiation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257245 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Una vulnerabilidad fue encontrada en Bdtask Wholesale Inventory Management System hasta 20240311 y ha sido declarada problemática. Una funcionalidad desconocida es afectada por esta vulnerabilidad. La manipulación conduce a la fijación de la sesión. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-257245. NOTA: Se contactó primeramente con el proveedor sobre esta divulgación, pero no respondió de ninguna manera.
In Bdtask Wholesale Inventory Management System bis 20240311 wurde eine problematische Schwachstelle ausgemacht. Es geht um eine nicht näher bekannte Funktion. Durch Beeinflussen mit unbekannten Daten kann eine session fixiation-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-03-19 CVE Reserved
- 2024-03-19 CVE Published
- 2024-03-20 EPSS Updated
- 2024-08-12 CVE Updated
- 2024-08-12 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-384: Session Fixation
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.257245 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://drive.google.com/file/d/1bNnSNssAeQFkO0FdW_yaEvDg5XExMPaf/view?usp=drivesdk | 2024-08-12 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bdtask Search vendor "Bdtask" | Multi Store Inventory Management System Search vendor "Bdtask" for product "Multi Store Inventory Management System" | * | - |
Affected
|