CVE-2024-24761
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 6, 2024
Updated: Dec 17, 2024
CWE ID 863
Summary
CVE-2024-24761: The Galette membership management web application, used by non-profit organizations, contains a default security misconfiguration. Prior to version 1.0.2, public pages were restricted only to administrators and staff members. This issue could potentially allow unauthorized access to public pages. Version 1.0.2 addresses this vulnerability by providing more configurable access options.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share