Medium5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

PT-2024-36: Calling arbitrary methods in Orchid Platform

Error type:

  • CWE-749:Exposed Dangerous Method or Function

Vulnerability vector:

  • Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
  • Severity (CVSSv3.1): 4.1 (medium)
  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
  • Severity (CVSSv4.0): 5.1 (medium)

Description:

The vulnerability was identified in Orchid Platform versions 8 - 14.42.x.
Discovered vulnerability can be exploited by an attacker to call arbitrary methods in the Screen class, which could lead to the ability to brute force database tables and disclosure of the server's IP address.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 06.11.2024

Recommendations:

  • Update to version 14.43.0 or higher

Additional information: Security advisory

Researcher: Vladislav Gladkiy (Positive Technologies)

Identifiers:

CVE-2024-51992

BDU:2024-09363

Vendor:

Orchid Software

Vulnerable product:

Orchid Platform

Vulnerable versions:

8 - 14.42.x