CVSS 3.1 Score 6.3 of 10 (medium)


Published Mar 22, 2024
Updated: Mar 25, 2024
CWE ID 611


A vulnerability (CVE-2024-2826) has been identified in lakernote EasyAdmin up to version 20240315. This vulnerability involves the manipulation of unknown code in the /ureport/designer/saveReportFile file, leading to xml external entity reference. The attack can be initiated remotely and has been publicly disclosed. The vulnerability is rated as medium severity with a base score of 6.3 according to CVSS:3.1 standards. It requires low privileges and does not require user interaction. The potential impact includes low integrity and confidentiality impacts, with a potential danger score of 25.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-2826 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options