CERT-In Vulnerability Note
CIVN-2024-0281
Multiple Vulnerabilities in Symphony XTS Trading platforms
Original Issue Date:September 03, 2024
Severity Rating: HIGH
Systems Affected
- Symphony XTS Web Trader version 2.0.0.1_P160
- Symphony XTS Mobile Trader version 2.0.0.1_P160
Overview
Multiple vulnerabilities have been reported in Symphony XTS Trader, which could allow an authenticated remote attacker to gain unauthorized access, modification or account takeover of other user accounts.
Description
1. Account Take Over Vulnerability
(
CVE-2024-45586
)
This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Trading and Mobile Trading platforms. An authenticated remote attacker could exploit this vulnerability by manipulating parameters through HTTP request which could lead to unauthorized account take over belonging to other users.
2. Unauthorized Modification Vulnerability
(
CVE-2024-45587
)
This vulnerability exists in Symphony XTS Web Trading platform due to improper access controls on APIs in the Transaction module of vulnerable application. An authenticated remote attacker could exploit this vulnerability by manipulating parameters through HTTP request which could lead to compromise of other user accounts.
3. Information Disclosure Vulnerability
(
CVE-2024-45588
)
This vulnerability exists in Symphony XTS Web Trading platform due to improper access controls on APIs in the Preference module of the application. An authenticated remote attacker could exploit this vulnerability by manipulating parameters through HTTP request which could lead to unauthorized access and modification of sensitive information belonging to other users.
Credit
These vulnerabilities are reported by Mohit Gadiya.
Solution
- Upgrade Symphony XTS Web Trader to version 2.0.0.1_P160_1 and
- Symphony XTS Mobile Trader to version 2.0.0.1_P160_1
Vendor Information
Symphony Fintech
https://symphonyfintech.com/xts/
References
Symphony Fintech
https://symphonyfintech.com/xts/
CVE Name
CVE-2024-45586
CVE-2024-45587
CVE-2024-45588
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|