7.5
CVE-2024-27292
- EPSS 93.83%
- Veröffentlicht 21.03.2024 02:52:19
- Zuletzt bearbeitet 02.09.2025 13:37:21
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jhpyle ≫ Docassemble Version >= 1.4.53 < 1.4.97
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 93.83% | 0.999 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-706 Use of Incorrectly-Resolved Name or Reference
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.