Back

HIGH

Insecure Authentication Vulnerability

Published Oct 4, 2024

Description

This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their corresponding mobile number. A remote attacker could exploit this vulnerability by providing mobile number of targeted user, to obtain complete access to the targeted user account.

Affected products

Remediation

Vendor solution

Upgrade Client Dashboard to version 9.7.0

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-In
Published Oct 4, 2024
Updated Oct 4, 2024
Reserved Sep 30, 2024
CISA Vulnrichment
Updated Oct 4, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a