CVE-2024-50617

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file path in the URL query string to retrieve the files. (Retrieval is not intended without correct data access configured for documents.)
Configurations

Configuration 1 (hide)

cpe:2.3:a:cipplanner:cipace:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-11 22:15

Updated : 2026-02-13 21:38


NVD link : CVE-2024-50617

Mitre link : CVE-2024-50617

CVE.ORG link : CVE-2024-50617


JSON object : View

Products Affected

cipplanner

  • cipace
CWE
CWE-285

Improper Authorization