CVE-2024-28735
Status: ModifiedHigh (8.1)—
Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Base score: 8.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.72%
- Percentile among all scored CVEs: 52
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-287
References
- https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html
- https://www.unit4.com/
- https://www.unit4.com/products/financial-management-software
- https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html
- https://www.unit4.com/
- https://www.unit4.com/products/financial-management-software
Raw JSON (NVD)
Show
{
"id": "CVE-2024-28735",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-28735",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-03-21T15:13:14.031303Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:coda:unit_4_financials:*:*:*:*:*:*:*:*"
],
"vendor": "coda",
"product": "unit_4_financials",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2023Q4",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-03-20T15:15:07.920",
"references": [
{
"url": "https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.unit4.com/",
"tags": [
"Product"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.unit4.com/products/financial-management-software",
"tags": [
"Product"
],
"source": "cve@mitre.org"
},
{
"url": "https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.unit4.com/",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.unit4.com/products/financial-management-software",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request."
},
{
"lang": "es",
"value": "Las versiones de Unit4 Financials by Coda anteriores al 2023Q4 sufren una vulnerabilidad de omisión de autorización de control de acceso incorrecto que permite a un usuario autenticado modificar la contraseña de cualquier usuario de la aplicación mediante una solicitud manipulada."
}
],
"lastModified": "2026-07-09T01:18:59.727",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:unit4:financials_by_coda:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3B7F43B0-CCAE-41A3-A07F-A29AC20F11FC",
"versionEndExcluding": "2023q4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}