Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-48201 Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 17 Mar 2025 18:45:00 +0900


Mon, 17 Mar 2025 17:45:00 +0900


Fri, 11 Oct 2024 01:30:00 +0900

Type Values Removed Values Added
Weaknesses CWE-286

Sat, 24 Aug 2024 00:30:00 +0900

Type Values Removed Values Added
First Time appeared Nask
Nask ezd Rp
Weaknesses CWE-863
CPEs cpe:2.3:a:nask:ezd_rp:*:*:*:*:*:*:*:*
Vendors & Products Nask
Nask ezd Rp
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 07 Aug 2024 22:30:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Aug 2024 20:00:00 +0900

Type Values Removed Values Added
Description Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.
Title Users listing in EZD RP
Weaknesses CWE-286
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/R:A/V:D/RE:L/U:Green'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2025-03-25T14:31:55.797Z

Reserved: 2024-07-30T08:43:02.704Z

Link: CVE-2024-7266

cve-icon Vulnrichment

Updated: 2024-08-07T13:08:30.566Z

cve-icon NVD

Status : Modified

Published: 2024-08-07T11:15:46.077

Modified: 2025-03-17T09:15:12.310

Link: CVE-2024-7266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses