CVE-2024-28345

A

n issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly visit the URL.

Configurations

Configuration 1 (hide)

cpe:2.3:a:sipwise:next_generation_communication_platform:*:*:*:*:-:*:*:*

History

17 Jun 2025, 17:08

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Sipwise
Sipwise next Generation Communication Platform
References () https://securitycafe.ro/2024/03/21/cve-2024-28344-cve-2024-28345-in-sipwise-c5/ - () https://securitycafe.ro/2024/03/21/cve-2024-28344-cve-2024-28345-in-sipwise-c5/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:sipwise:next_generation_communication_platform:*:*:*:*:-:*:*:*

06 Dec 2024, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

21 Nov 2024, 09:06

Type Values Removed Values Added
Summary
  • (es) Un problema descubierto en el panel de control de Sipwise C5 NGCP por debajo de mr11.5.1 permite que un usuario con pocos privilegios acceda al endpoint del diario visitando directamente la URL.
References () https://securitycafe.ro/2024/03/21/cve-2024-28344-cve-2024-28345-in-sipwise-c5/ - () https://securitycafe.ro/2024/03/21/cve-2024-28344-cve-2024-28345-in-sipwise-c5/ -

Information

Published : 2024-04-10 19:15

Updated : 2025-06-17 17:08


NVD link : CVE-2024-28345

Mitre link : CVE-2024-28345

CVE.ORG link : CVE-2024-28345


JSON object : View