We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-12123

Unauthorized Modification of Ticket Requester



Description

A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user.  When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy.  The ticket requester can be changed from the original requester to another user in the same application, which the application then accepts.

Reserved 2024-12-03 | Published 2024-12-04 | Updated 2024-12-04 | Assigner Gridware


MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-472: External Control of Assumed-Immutable Web Parameter

CWE-837 Improper Enforcement of a Single, Unique Action

Product status

Default status
unaffected

Issuetrak 17.1
affected

Credits

Harrison Daley finder

References

helpcenter.issuetrak.com/home/2340-issuetrak-release-notes

cve.org (CVE-2024-12123)

nvd.nist.gov (CVE-2024-12123)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-12123

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.