Vulnerability CVE-2024-49373


Published: 2024-10-22   Modified: 2024-10-23

Description:
No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations they are not apart of. Version 1.2.1 fixes the problem.

Type:

CWE-653

(Insufficient Compartmentalization)

 References:
https://github.com/nofusscomputing/centurion_erp/security/advisories/GHSA-5qmx-pr2f-qhj5
https://github.com/nofusscomputing/centurion_erp/pull/358
https://github.com/nofusscomputing/centurion_erp/commit/c3a4685200faa060167d4fde86e806dc91eddcae

Copyright 2024, cxsecurity.com

 

Back to Top