CVE-2024-12123
A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy. The ticket requester can be changed from the original requester to another user in the same application, which the application then accepts.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.36%
- CWE
- CWE-472, CWE-837
- Published
- 2024-12-04
- Last modified
- 2026-03-13
Affected products
- Issuetrak Issuetrak
Weakness type
Related vulnerabilities
- CVE-2026-84762 — WordPress WP EasyPay plugin <= 4.5.3 - Bypass Vulnerability vulnerability
- CVE-2026-77999 — Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
- CVE-2026-67363 — Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
- CVE-2026-1982 — Persian Elementor (المنتور فارسی) <= 2.8.1 - Unauthenticated Price Manipulation via ZarinPal Widget
- CVE-2026-7484 — Improper Access Control in Abis Technology's AVESİS
- CVE-2026-65052 — Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields
- CVE-2026-16089 — Keycloak-services: keycloak-services: authorization codes can be retargeted to another client session
- CVE-2026-56877 — The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not...