CVE-2024-29837
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.51%
- CWE
- CWE-284, CWE-1390
- Published
- 2024-04-14
- Last modified
- 2026-03-13
Affected products
- CS Technologies Australia Evolution Controller
Weakness type
Related vulnerabilities
- CVE-2026-79725 — Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation
- CVE-2026-81941 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-81046 — Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure...
- CVE-2026-88864 — Capgo SSO Provider Authentication Bypass via PostgREST Direct Write
- CVE-2026-78084 — Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4
- CVE-2026-50165 — alf.io has Improper Access Control for Organization Owners that Exposes System Secrets
- CVE-2026-86774 — Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
- CVE-2026-19625 — IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities