Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 18 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mgt-commerce
Mgt-commerce cloudpanel |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:mgt-commerce:cloudpanel:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Mgt-commerce
Mgt-commerce cloudpanel |
|
| Metrics |
cvssV3_1
|
Mon, 11 Nov 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH v2.0.0 to v2.4.2 allows attackers to escalate privileges and access sensitive information via manipulation of the Nginx configuration file. | An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access to sensitive configuration files and administrative functionality. |
Fri, 08 Nov 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH v2.0.0 to v2.4.2 allows attackers to escalate privileges and access sensitive information via manipulation of the Nginx configuration file. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-18T14:03:37.382Z
Reserved: 2024-08-21T00:00:00.000Z
Link: CVE-2024-44765
Updated: 2024-11-18T14:03:15.521Z
Status : Deferred
Published: 2024-11-08T19:15:05.590
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-44765
No data.
OpenCVE Enrichment
No data.