CVE-2024-27292
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.
7.5
CVSS
69.5%
EPSS (exploit prob.)
99th
EPSS percentile
2024-03-21
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-706
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| jhpyle | docassemble | >= 1.4.53, < 1.4.97 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/jhpyle/docassemble/commit/97f77dc486a26a22ba804765bfd7058aabd600c9
- https://github.com/jhpyle/docassemble/security/advisories/GHSA-jq57-3w7p-vwvv
- https://github.com/jhpyle/docassemble/commit/97f77dc486a26a22ba804765bfd7058aabd600c9
- https://github.com/jhpyle/docassemble/security/advisories/GHSA-jq57-3w7p-vwvv
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-27292