Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users.This issue affects Managment Portal: through 21.05.2024.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.usom.gov.tr/bildirim/tr-24-1356 |
|
History
Tue, 14 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 |
Tue, 14 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Privilege Management vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users.This issue affects Managment Portal: through 21.05.2024. | Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users.This issue affects Managment Portal: through 21.05.2024. |
| Weaknesses | CWE-306 CWE-862 |
Fri, 30 Aug 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Menulux managment Portal
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:menulux:managment_portal:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Menulux managment Portal
|
|
| Metrics |
cvssV3_1
|
Thu, 29 Aug 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Menulux
Menulux management Portal |
|
| CPEs | cpe:2.3:a:menulux:management_portal:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Menulux
Menulux management Portal |
|
| Metrics |
ssvc
|
Thu, 29 Aug 2024 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Privilege Management vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users.This issue affects Managment Portal: through 21.05.2024. | |
| Title | Sensetive Data Exposure in Menulux Managment Portal | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TR-CERT
Published: 2024-08-29T07:49:03.112Z
Updated: 2025-10-14T12:47:02.670Z
Reserved: 2024-05-02T12:32:52.001Z
Link: CVE-2024-4428
Updated: 2024-08-29T13:32:56.462Z
Status : Modified
Published: 2024-08-29T11:15:27.200
Modified: 2025-10-14T13:15:35.530
Link: CVE-2024-4428
No data.