Vulnerability Description
Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to vis_client_id.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/websec/Vision-Helpdesk-Exploit
- https://websec.net/blog/critical-vulnerability-in-vision-helpdesk-allows-unautho
FAQ
What is CVE-2024-58343?
CVE-2024-58343 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to vis_client_id.
How severe is CVE-2024-58343?
CVE-2024-58343 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-58343?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.