Back to Database
Status published
Unknown
CVE-2024-10469
CERT/CC VINCE versions before 3.0.9 allows authenticated user to access User Management view.
Vulnerability Description
VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10469
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This issues was reported by an internal user of VINCE
References
More from CERT/CC
View All →CVE-2024-9953
Potential DoS Vulnerability in CERT VINCE Software Before Version 3.0.8
Unknown
0
CVE-2022-40257
An HTML injection vulnerability exists in CERT/CC VINCE software prior to version 1.50.4
Medium
5.4
CVE-2022-40248
An HTML injection vulnerability exists in CERT/CC VINCE software prior to version 1.50.4
Medium
5.4
CVE-2022-40238
A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5
Unknown
0
CVE-2022-25799
An open redirect vulnerability exists in CERT/CC VINCE software prior to version 1.50.0
Medium
6.1
Affected Vendor
CERT/CC
View all reports →Affected Software
VINCE
Vulnerable Versions:
*
Timeline
Official Publish:
October 28th, 2024
Last Modified:
August 25th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available