CVE-2024-47089: Apexsoftcell Ld Dp Back Office

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating the transaction token ID in the API request leading to unauthorized access and modification of transactions belonging to other users.

Affected products

  • Apexsoftcell Ld Dp Back Office: before 24.8.21.1 (fixed in 24.8.21.1)
  • Apexsoftcell Ld Geo: before 4.0.0.7 (fixed in 4.0.0.7)

Published 2024-09-19. Last modified 2026-06-17.