CVE-2024-30516
Improper Quantity Validation in SaasProject Booking Enables Unauthorized Access
Publication date: 2026-01-05
Last updated on: 2026-01-05
Assigner: Patchstack
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| saasproject | booking_package | to 1.6.27 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1284 | The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Improper Validation of Specified Quantity in Input in the SaasProject Booking Package, which allows accessing functionality that is not properly constrained by Access Control Lists (ACLs). This means that users may be able to perform actions or access features they should not have permission to use.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing unauthorized users to access or manipulate functionality within the Booking Package that should be restricted. This can lead to unauthorized actions being performed, potentially compromising the integrity of the system or data.