We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-49373

Centurion ERP user can view projects from organizations they're not apart of



Description

No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations they are not apart of. Version 1.2.1 fixes the problem.

Reserved 2024-10-14 | Published 2024-10-22 | Updated 2024-10-22 | Assigner GitHub_M


MEDIUM: 4.1CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Problem types

CWE-653: Improper Isolation or Compartmentalization

Product status

< 1.2.1
affected

References

github.com/...on_erp/security/advisories/GHSA-5qmx-pr2f-qhj5

github.com/nofusscomputing/centurion_erp/pull/358

github.com/...ommit/c3a4685200faa060167d4fde86e806dc91eddcae

cve.org (CVE-2024-49373)

nvd.nist.gov (CVE-2024-49373)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-49373

Support options

Helpdesk Chat, Email, Knowledgebase