SB2024070333 - Multiple vulnerabilities in Talya Informatics Travel APPS 



SB2024070333 - Multiple vulnerabilities in Talya Informatics Travel APPS

Published: July 3, 2024

Security Bulletin ID SB2024070333
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Improper access control (CVE-ID: CVE-2024-1153)

The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. An attacker with physical access can bypass implemented security restrictions and obtain sensitive information


2) Authorization bypass through user-controlled key (CVE-ID: CVE-2024-1107)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to authorization bypass through user-controlled key. A remote user can send a specially crafted request and bypass authorization.


Remediation

Install update from vendor's website.