CVE-2024-4538
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-4538 is a new IDOR (Insecure Direct Object References) vulnerability identified in Janto Ticketing Software version 4.3r10. This issue permits a remote user to gain unauthorized access to another user's event ticket data by crafting a specific request using the ticket reference ID. Successful exploitation of this vulnerability may result in the exposure of sensitive user information related to ticket details. The impact of this vulnerability could potentially lead to unintended ticket purchases, data breaches, or further unauthorized actions. It is recommended that users upgrade to the latest software version with the necessary patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.