CVE-2024-12048
CVSS 3.0 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-12048 is an IDOR (Insecure Direct Object Reference) vulnerability affecting transformeroptimus/superagi version v0.0.14. The application fails to enforce proper authorization checks on several API endpoints, including /get/project/{project_id}, /get/schedule_data/{agent_id}, /delete/{agent_id}, /get/organisation/{organisation_id}, and /get/user/{user_id}. Due to this issue, unauthorized users can gain access to, modify, and delete other users' information, potentially leading to significant data breaches. Users are advised to update their software to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.