CVE-2024-3164
CVSS 3.1 Score 4.5 of 10 (medium)
Details
Published Apr 1, 2024
Updated: Jul 26, 2024
CWE ID 552
Summary
CVE-2024-3164 is a vulnerability affecting dotCMS that allows users with site admin roles to access the Tools and Log Files tabs under System → Maintenance Portlet, which should only be accessible to system admins. This issue, classified as Broken Access Control (OWASP Top 10 A01) and Insecure Design (OWASP Top 10 A04), exposes sensitive information such as database credentials and allows the download of dotCMS content. Unauthorized users should not have access to System Maintenance, and this vulnerability undermines the intended access control measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Dotcms