CVE-2024-24761

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 6, 2024
Updated: Dec 17, 2024
CWE ID 863

Summary

CVE-2024-24761: The Galette membership management web application, used by non-profit organizations, contains a default security misconfiguration. Prior to version 1.0.2, public pages were restricted only to administrators and staff members. This issue could potentially allow unauthorized access to public pages. Version 1.0.2 addresses this vulnerability by providing more configurable access options.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share