Skip to main content

DEPRECATED: Authentication Bypass Issues

CVE-2024-42759

Severity Medium
Score 6.3/10

Summary

An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.

  • LOW
  • LOCAL
  • HIGH
  • UNCHANGED
  • NONE
  • HIGH
  • HIGH
  • LOW

CWE-592 - DEPRECATED: Authentication Bypass Issues

This weakness has been deprecated because it covered redundant concepts already described in CWE-287.

References

Advisory Timeline

  • Published