CVE-2024-12776

CVSS 3.0 Score 8.1 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 305

Summary

CVE-2024-12776 is a vulnerability affecting the `/forgot-password/resets` endpoint in langgenius/dify version 0.10.1. The flaw allows an attacker to bypass password reset code verification, enabling them to reset the passwords of any user, including administrators. This vulnerability poses a significant risk, as successful exploitation can result in complete compromise of the application.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share