Omission of key-controlled authorization in Qsige
Vulnerability Description
Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerability allows an attacker to extract sensitive information from the API by making a request to the parameter '/qsige.locator/quotePrevious/centers/X', where X supports values 1,2,3, etc.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-0580
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Oscar Atienza
Affected Vendor
IDMSistemas
View all reports →