CVE Vulnerabilities

CVE-2024-6425

Incorrect Provision of Specified Functionality

Published: Jul 01, 2024 | Modified: Oct 22, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can register user accounts without being authenticated from the route /account/Register/ and in the parameters UserName=&Password=&ConfirmPassword=.

Weakness

The code does not function according to its published specifications, potentially leading to incorrect usage.

Affected Software

NameVendorStart VersionEnd Version
MesbookMesbook20221021.03 (including)20221021.03 (including)

Potential Mitigations

References