CVE-2024-49373 MEDIUM

CVE-2024-49373: Centurion ERP user can view projects from organizations they're not apart of

Vendor Nofusscomputing
Product centurion_erp
Weakness CWE-653
Published October 22, 2024
Last update October 22, 2024

CVSS base score

4.1/10
Attack vector Physical
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations they are not apart of. Version 1.2.1 fixes the problem.

Key dates

02Disclosure timeline

October 22, 2024 CVE published
October 22, 2024 Record updated