CVE-2024-31845: Medium severity italtel embrace vulnerability
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31845?
CVE-2024-31845 is considered a medium severity vulnerability due to its impact on log integrity.
How do I fix CVE-2024-31845?
To fix CVE-2024-31845, ensure proper sanitization of input data before writing it to logs in Italtel Embrace 1.6.4.
What type of vulnerability is CVE-2024-31845?
CVE-2024-31845 is a log injection vulnerability that allows attackers to manipulate log entries.
Which software versions are affected by CVE-2024-31845?
CVE-2024-31845 affects Italtel Embrace version 1.6.4.
What can an attacker achieve by exploiting CVE-2024-31845?
An attacker exploiting CVE-2024-31845 can compromise the integrity of log files, leading to misleading information and possible unauthorized actions being attributed.