Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54657 | In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated by /api/v1/users/resetpassword. |
Fri, 13 Jun 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 09 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 07 Jun 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access. | In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated by /api/v1/users/resetpassword. |
Sat, 07 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | moPS App Engine 1.8.618 has incorrect access control. | In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access. |
| Weaknesses | CWE-306 | |
| Metrics |
cvssV4_0
|
Sat, 07 Jun 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | moPS App Engine 1.8.618 has incorrect access control. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-13T07:27:37.060Z
Reserved: 2024-12-09T00:00:00.000Z
Link: CVE-2024-55585
Updated: 2025-06-09T15:12:39.760Z
Status : Deferred
Published: 2025-06-07T19:15:22.333
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-55585
No data.
OpenCVE Enrichment
No data.
EUVD