CVE-2024-12048

CVSS 3.0 Score 8.8 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 304

Summary

CVE-2024-12048 is an IDOR (Insecure Direct Object Reference) vulnerability affecting transformeroptimus/superagi version v0.0.14. The application fails to enforce proper authorization checks on several API endpoints, including /get/project/{project_id}, /get/schedule_data/{agent_id}, /delete/{agent_id}, /get/organisation/{organisation_id}, and /get/user/{user_id}. Due to this issue, unauthorized users can gain access to, modify, and delete other users' information, potentially leading to significant data breaches. Users are advised to update their software to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share