High severity8.1NVD Advisory· Published Mar 20, 2024· Updated Jul 9, 2026
CVE-2024-28735
CVE-2024-28735
Description
Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:unit4:financials_by_coda:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:unit4:financials_by_coda:*:*:*:*:*:*:*:*range: <2023q4
- (no CPE)range: <2023Q4
- Unit4/Financials by Codadescription
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.htmlnvdExploitThird Party Advisory
- www.unit4.comnvdProduct
- www.unit4.com/products/financial-management-softwarenvdProduct
News mentions
0No linked articles in our index yet.