CVE-2024-6534
CVE-2024-6534
Título es
CVE-2024-6534
Jue, 15/08/2024 – 04:15
Tipo
CWE-639
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-6534
Descripción en
Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because the application only validates the user parameter in the 'POST /presets' request but not in the PATCH request. When chained with CVE-2024-6533, it could result in account takeover.
15/08/2024
15/08/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
4.10
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Enviar en el boletín
Off
