CVE-2024-33860
- EPSS 0.23%
- Veröffentlicht 07.05.2024 17:15:09
- Zuletzt bearbeitet 18.04.2025 12:32:57
An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System Collector. The content of the file specified can be viewed in the incoming logs.
CVE-2024-33859
- EPSS 0.51%
- Veröffentlicht 07.05.2024 17:15:09
- Zuletzt bearbeitet 18.04.2025 12:35:55
An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting Field" Web UI, leading to XSS.
CVE-2024-33858
- EPSS 0.22%
- Veröffentlicht 07.05.2024 16:15:08
- Zuletzt bearbeitet 18.04.2025 12:38:04
An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The source_name parameter could be changed to an absolute path; this will write the CSV file to that path inside the /tmp d...
CVE-2024-33857
- EPSS 0.21%
- Veröffentlicht 07.05.2024 16:15:08
- Zuletzt bearbeitet 18.04.2025 12:39:11
An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access to the system can trigger Server Side Request Forgery.
CVE-2024-33856
- EPSS 0.37%
- Veröffentlicht 07.05.2024 16:15:08
- Zuletzt bearbeitet 18.04.2025 12:39:50
An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot Password endpoint.
CVE-2024-30176
- EPSS 0.26%
- Veröffentlicht 01.05.2024 18:15:19
- Zuletzt bearbeitet 22.04.2025 17:53:35
In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets.
CVE-2022-48685
- EPSS 0.04%
- Veröffentlicht 27.04.2024 23:15:06
- Zuletzt bearbeitet 18.04.2025 19:15:11
An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by all users and is executed as root, leading to privilege escalation.
CVE-2022-48684
- EPSS 0.26%
- Veröffentlicht 27.04.2024 23:15:06
- Zuletzt bearbeitet 18.04.2025 19:06:28
An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jinja templating for generating dynamic data. This could be abused to achieve code execution. Any user with access to creat...
CVE-2024-29865
- EPSS 0.51%
- Veröffentlicht 22.03.2024 15:15:15
- Zuletzt bearbeitet 16.04.2025 18:44:43
Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.
CVE-2023-49950
- EPSS 0.18%
- Veröffentlicht 03.02.2024 09:15:11
- Zuletzt bearbeitet 17.06.2025 16:15:25
The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template in the Alert view. A remote attacker can craft a cross-site scripting (XSS) payload and send...