Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53556 | Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a vulnerability in access control mechanisms by removing authentication-related HTTP headers, such as the Cookie header, in the request. This bypasses the authentication process and grants attackers access to sensitive image files without proper login credentials. |
Mon, 15 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gleamtech:filevista:9.2.0:*:*:*:*:*:*:* |
Tue, 11 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 10 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Fri, 07 Feb 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a vulnerability in access control mechanisms by removing authentication-related HTTP headers, such as the Cookie header, in the request. This bypasses the authentication process and grants attackers access to sensitive image files without proper login credentials. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-11T15:21:05.499Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57249
Updated: 2025-02-10T17:31:31.681Z
Status : Analyzed
Published: 2025-02-07T16:15:38.180
Modified: 2025-09-15T18:02:51.267
Link: CVE-2024-57249
No data.
OpenCVE Enrichment
Updated: 2025-07-21T15:17:08Z
EUVD