Vulnerabilities > CVE-2024-10439 - Authorization Bypass Through User-Controlled Key vulnerability in Sun.Net Ehdr Ctms

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
sun-net
CWE-639

Summary

The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.

Vulnerable Configurations

Part Description Count
Application
Sun.Net
1