CVE-2024-9097

Published Feb 5, 2025

Last updated 23 days ago

Overview

Description
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.
Source
0fc0942c-577d-436f-ae8e-945763c79b02
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
3.5
Impact score
1.4
Exploitability score
2.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Severity
LOW

Weaknesses

0fc0942c-577d-436f-ae8e-945763c79b02
CWE-639

Social media

Hype score
Not currently trending