CVE Vulnerabilities

CVE-2024-49373

Improper Isolation or Compartmentalization

Published: Oct 22, 2024 | Modified: Oct 30, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations they are not apart of. Version 1.2.1 fixes the problem.

Weakness

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Affected Software

Name Vendor Start Version End Version
Centurion_erp Nofusscomputing * 1.2.1 (excluding)

Potential Mitigations

References