First published: Mon Jan 29 2024(Updated: )
A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulnerability is the function checklogin of the file /application/index/common.php. The manipulation of the argument App_User_id/App_user_Token leads to improper authentication. The exploit has been disclosed to the public and may be used. The identifier VDB-252253 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kuerp Project Kuerp | <=1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0988 is classified as a critical severity vulnerability.
To fix CVE-2024-0988, update Sichuan Yougou Technology KuERP to version 1.0.5 or later.
CVE-2024-0988 affects the checklogin function in the file /application/index/common.php.
The potential impact of CVE-2024-0988 includes improper authentication due to manipulated user tokens.
Versions of KuERP up to and including 1.0.4 are vulnerable to CVE-2024-0988.