CVE-2024-8261 Details
Description
Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OBS: before 24.0927.
An authorization bypass vulnerability has been identified in Proliz Software's OBS (Öğrenci İşleri Bilgi Sistemi) application, prior to version 24.0927. This vulnerability allows exploitation of incorrectly configured access control security levels, potentially enabling cyber attackers to manipulate access controls and perform unauthorized actions.
Users and system administrators are advised to upgrade to version 24.0927 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0049 | [email protected] | |
| https://www.usom.gov.tr/bildirim/tr-25-0049 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| prolizyazilim student affairs information system | < 24.0927 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 2, 2026 | CVE Modified | [email protected] |
| Sep 12, 2025 | CVE Modified | [email protected] |
| Mar 10, 2025 | CVE Modified | [email protected] |
| Mar 7, 2025 | Initial Analysis | [email protected] |
| Mar 3, 2025 | New CVE Received | [email protected] |