CVE Vulnerabilities

CVE-2024-47652

Use of Single-factor Authentication

Published: Oct 04, 2024 | Modified: Oct 16, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their corresponding mobile number. A remote attacker could exploit this vulnerability by providing mobile number of targeted user, to obtain complete access to the targeted user account.

Weakness

The product uses an authentication algorithm that uses a single factor (e.g., a password) in a security context that should require more than one factor.

Affected Software

NameVendorStart VersionEnd Version
Client_dashboardShilpisoft*9.7.0 (excluding)

Potential Mitigations

References