CVE-2024-47087
This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
- EPSS probability
- 0.44%
- CWE
- CWE-359
- Published
- 2024-09-19
- Last modified
- 2026-03-13
Affected products
- Apex Softcell LD Geo
Weakness type
Related vulnerabilities
- CVE-2026-73008 — Windows Biometric Service Information Disclosure Vulnerability
- CVE-2026-69351 — Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability
- CVE-2026-21827 — HCL Connections is vulnerable to an information disclosure vulnerability
- CVE-2026-53497 — CrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active session metadata (IP, User-Agent, session IDs)
- CVE-2026-58510 — GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- CVE-2026-48048 — XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests
- CVE-2026-24078 — Exposure of Private Personal Information to an Unauthorized Actor in Data Modem
- CVE-2026-55496 — Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate