CVE-2024-29839: Cs-Technologies Evolution
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user
Affected products
- Cs-Technologies Evolution: up to and including 2.04.560
Published 2024-04-15. Last modified 2026-06-17.