CVE Vulnerabilities

CVE-2024-6425

Incorrect Provision of Specified Functionality

Published: Jul 01, 2024 | Modified: Jul 01, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can register user accounts without being authenticated from the route /account/Register/ and in the parameters UserName=&Password=&ConfirmPassword=.

Weakness

The code does not function according to its published specifications, potentially leading to incorrect usage.

Potential Mitigations

References