CVE-2025-66361
- EPSS 0.05%
- Veröffentlicht 27.11.2025 00:00:00
- Zuletzt bearbeitet 03.12.2025 19:15:03
An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load.
CVE-2025-66360
- EPSS 0.06%
- Veröffentlicht 27.11.2025 00:00:00
- Zuletzt bearbeitet 03.12.2025 19:12:44
An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) information to li-admin users. This can lead to privilege escalation.
CVE-2025-66359
- EPSS 0.05%
- Veröffentlicht 27.11.2025 00:00:00
- Zuletzt bearbeitet 03.12.2025 19:08:50
An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multiple components leads to a cross-site scripting (XSS) vulnerability.
CVE-2024-56087
- EPSS 0.12%
- Veröffentlicht 16.12.2024 06:15:07
- Zuletzt bearbeitet 17.04.2025 01:50:51
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
CVE-2024-56086
- EPSS 1.97%
- Veröffentlicht 16.12.2024 06:15:07
- Zuletzt bearbeitet 17.04.2025 01:50:13
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.
CVE-2024-56085
- EPSS 0.12%
- Veröffentlicht 16.12.2024 06:15:07
- Zuletzt bearbeitet 17.04.2025 01:48:50
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
CVE-2024-48950
- EPSS 0.12%
- Veröffentlicht 07.11.2024 17:15:08
- Zuletzt bearbeitet 18.04.2025 13:12:45
An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and authentication.
CVE-2024-48954
- EPSS 1.82%
- Veröffentlicht 07.11.2024 17:15:08
- Zuletzt bearbeitet 30.04.2025 16:42:20
An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.
CVE-2024-48953
- EPSS 0.24%
- Veröffentlicht 07.11.2024 17:15:08
- Zuletzt bearbeitet 30.04.2025 16:35:55
An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in L...
CVE-2024-48951
- EPSS 0.11%
- Veröffentlicht 07.11.2024 17:15:08
- Zuletzt bearbeitet 30.04.2025 16:36:17
An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.