CVE Database
/

CVE-2024-28143

Back to search

CVE-2024-28143

Published: Dec 12, 2024

Modified: Nov 3, 2025

PUBLISHED

Description

The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing the old password, e.g. by exploiting a CSRF issue.

VendorProductVersions

Image Access GmbH

Scan2Net

affected
0 - < 7.40

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now