Medium severity6.5NVD Advisory· Published Sep 9, 2024· Updated Jun 17, 2026
CVE-2024-8601
CVE-2024-8601
Description
This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to unauthorized access to sensitive information belonging to other users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:techexcel:back_office_software:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:techexcel:back_office_software:*:*:*:*:*:*:*:*range: <1.0.0
- (no CPE)range: <1.0.0
- Range: <1.0.0
Patches
Vulnerability mechanics
References
1- www.cert-in.org.in/s2cMainServletnvdThird Party Advisory
News mentions
0No linked articles in our index yet.