Missing Origin Validation in WebSockets
CVE-2024-48849
Summary
Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- LOW
- HIGH
CWE-1385 - Missing Origin Validation in WebSockets
The software uses a WebSocket, but it does not properly verify that the source of data or communication is valid.
References
Advisory Timeline
- Published