Unrated severityNVD Advisory· Published Oct 28, 2024· Updated Oct 28, 2024
Sunnet eHRD CTMS - Insecure Direct Object Reference
CVE-2024-10439
Description
The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.twcert.org.tw/en/cp-139-8167-a2c0d-2.htmlmitrethird-party-advisory
- www.twcert.org.tw/tw/cp-132-8166-085c4-1.htmlmitrethird-party-advisory
News mentions
0No linked articles in our index yet.