CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-38783

Medium Severity
SVRS
30/100

CVSSv3
5.3/10

EPSS
0.00048/1

CVE-2024-38783: A missing authorization vulnerability exists in Tyche Softwares Arconix FAQ versions up to 1.9.4, potentially allowing unauthorized access to functionalities. This Arconix FAQ vulnerability enables attackers to bypass intended access controls (ACLs). With a SOCRadar Vulnerability Risk Score (SVRS) of 30, while not immediately critical, this vulnerability should be addressed in due course. The CVSS score is 5.3. Exploitation of this vulnerability could lead to unauthorized manipulation of FAQ settings and content, potentially damaging the integrity of the website. While the SVRS suggests a moderate level of immediate risk, patching is advised to mitigate potential future threats. Organizations using the affected Arconix FAQ versions should update to a secure version as soon as possible.

No tags available
CVSS:3.1
AV:N
AC:L
PR:N
UI:N
S:U
C:N
I:L
A:N
2024-11-01

2025-03-20

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-38783 | Tyche Softwares Arconix FAQ Plugin up to 1.9.4 on WordPress authorization
vuldb.com2025-03-21
CVE-2024-38783 | Tyche Softwares Arconix FAQ Plugin up to 1.9.4 on WordPress authorization | A vulnerability classified as problematic has been found in Tyche Softwares Arconix FAQ Plugin up to 1.9.4 on WordPress. Affected is an unknown function. The manipulation leads to missing authorization. This vulnerability is traded as CVE-2024-38783. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
rss
forum
news

Social Media

CVE-2024-38783 Missing Authorization vulnerability in Tyche Softwares Arconix FAQ allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Arconix FAQ: fro… https://t.co/CFMEVtziNg
0
0
0

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://patchstack.com/database/vulnerability/arconix-faq/wordpress-arconix-faq-plugin-1-9-4-broken-access-control-vulnerability?_s_id=cve
[email protected]https://patchstack.com/database/vulnerability/arconix-faq/wordpress-arconix-faq-plugin-1-9-4-broken-access-control-vulnerability?_s_id=cve

CWE Details

CWE IDCWE NameDescription
CWE-862Missing AuthorizationThe software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence