CVE-2024-45787
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL and intercepting response of the API request leading to exposure of sensitive information belonging to other users.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
- EPSS probability
- 0.44%
- CWE
- CWE-359
- Published
- 2024-09-11
- Last modified
- 2026-03-13
Affected products
- Reedos Software Solutions Mutual Fund Distribution Product (aiM-Star)
Weakness type
Related vulnerabilities
- CVE-2022-0482 — Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
- CVE-2024-45591 — XWiki Platform document history including authors of any page exposed to unauthorized actors
- CVE-2023-50719 — XWiki Platform Solr search discloses password hashes of all users
- CVE-2024-11396 — Event monster <= 1.4.3 - Information Exposure Via Visitors List Export
- CVE-2022-2921 — Exposure of Private Personal Information to an Unauthorized Actor in notrinos/notrinoserp
- CVE-2022-1365 — Exposure of Private Personal Information to an Unauthorized Actor in lquixada/cross-fetch
- CVE-2025-54125 — XWiki Platform: Password and email exposure in xml.vm fields
- CVE-2025-53625 — DynamicPageList3 exposes hidden/suppressed usernames