Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command Injection, Collect Data from Common Resource Locations.
This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.usom.gov.tr/bildirim/tr-24-1611 |
|
History
Tue, 14 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-311 |
Tue, 14 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cleartext Storage of Sensitive Information vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data.This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03. | Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command Injection, Collect Data from Common Resource Locations. This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03. |
Tue, 12 Nov 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Finrota
Finrota finrota |
|
| CPEs | cpe:2.3:a:finrota:finrota:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Finrota
Finrota finrota |
|
| Metrics |
cvssV3_1
|
Fri, 04 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Oct 2024 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cleartext Storage of Sensitive Information vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data.This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03. | |
| Title | Cleartext Storage of Username and Password in Finrota's Netahsilat | |
| Weaknesses | CWE-202 CWE-311 CWE-312 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TR-CERT
Published: 2024-10-04T11:12:30.441Z
Updated: 2025-10-14T12:55:46.692Z
Reserved: 2024-06-28T11:59:51.082Z
Link: CVE-2024-6400
Updated: 2024-10-04T13:59:53.252Z
Status : Modified
Published: 2024-10-04T12:15:12.930
Modified: 2025-10-14T13:15:35.883
Link: CVE-2024-6400
No data.