First published: Fri Nov 01 2024(Updated: )
Missing Authorization vulnerability in E2Pdf.Com allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects e2pdf: from n/a through 1.20.27.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
E2Pdf | <=1.20.27 | |
E2Pdf | <=1.20.27 |
Update to 1.23.00 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37415 is classified as a missing authorization vulnerability that can lead to exploitation due to incorrectly configured access control security levels.
To fix CVE-2024-37415, update the E2Pdf plugin to version 1.20.28 or later, as this version addresses the access control issues.
CVE-2024-37415 affects E2Pdf from versions n/a through 1.20.27.
CVE-2024-37415 affects both the E2Pdf software and the WordPress E2Pdf plugin.
The potential risks of CVE-2024-37415 include unauthorized access to sensitive data due to improper access control.