CVE-2024-3122: Changing Mobile One Time Password

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.

Affected products

Published 2024-07-01. Last modified 2026-06-17.