fkie_cve-2024-2730
Vulnerability from fkie_nvd
Published
2024-04-10 14:15
Modified
2024-11-21 09:10
Severity ?
Summary
Mautic uses predictable page indices for unpublished landing pages, their content can be accessed by unauthenticated users under public preview URLs which could expose sensitive data. At the time of publication of the CVE no patch is available
References
Impacted products
Vendor | Product | Version |
---|
{ "cveTags": [], "descriptions": [ { "lang": "en", "value": "Mautic uses predictable page indices for unpublished landing pages, their content can be accessed by unauthenticated users under public preview URLs which could expose sensitive data. At the time of publication of the CVE no patch is available \n\n" }, { "lang": "es", "value": "Mautic utiliza \u00edndices de p\u00e1ginas predecibles para p\u00e1ginas de destino no publicadas; usuarios no autenticados pueden acceder a su contenido a trav\u00e9s de URL de vista previa p\u00fablicas que podr\u00edan exponer datos confidenciales. En el momento de publicaci\u00f3n del CVE no hay ning\u00fan parche disponible" } ], "id": "CVE-2024-2730", "lastModified": "2024-11-21T09:10:23.560", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "vulnerability@ncsc.ch", "type": "Secondary" } ] }, "published": "2024-04-10T14:15:07.550", "references": [ { "source": "vulnerability@ncsc.ch", "url": "https://huntr.com/bounties/cd3321a4-9ebc-48fa-8d4c-b5720089c2d9" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://huntr.com/bounties/cd3321a4-9ebc-48fa-8d4c-b5720089c2d9" } ], "sourceIdentifier": "vulnerability@ncsc.ch", "vulnStatus": "Awaiting Analysis", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-425" } ], "source": "vulnerability@ncsc.ch", "type": "Secondary" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…