First published: Fri Nov 01 2024(Updated: )
Missing Authorization vulnerability in AyeCode Ltd GetPaid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GetPaid: from n/a through 2.8.11.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ayecode Getpaid | <2.8.12 |
Update to 2.8.12 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-43973 is classified as high due to the potential for unauthorized access to sensitive data.
To fix CVE-2024-43973, upgrade AyeCode GetPaid to version 2.8.12 or later to ensure proper access control is enforced.
CVE-2024-43973 affects AyeCode GetPaid versions from n/a through 2.8.11.
CVE-2024-43973 involves a missing authorization vulnerability allowing exploitation due to incorrectly configured access controls.
Yes, CVE-2024-43973 can be exploited remotely if the affected version is publicly accessible.