go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Heimavista Rpage and Epage - Broken Access Control

TVN ID TVN-202403001
CVE ID CVE-2024-2412
CVSS 5.3 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products rpage v5.4.103.20231111 or earlier version
epage v3.0.106.20231112 or earlier version
Description The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be disabled.
Solution Update Rpage to versions later than v5.4.103.20231111
Update Epage to versions later than v3.0.106.20231112
Credit Marvin Pai-Lun Chang(Digicentre Company Limited)
Public Date 2024-03-15
Top