CVE-2024-47768
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Oct 4, 2024
Updated: Nov 13, 2024
CWE ID 287
CWE ID 862
Summary
CVE-2024-47768 is a vulnerability affecting Lif Authentication Server, used by Lif for account-related tasks. The account recovery system, which allows users to regain access to their accounts if they have lost or forgotten their passwords, does not include adequate checks. An attacker who knows a target's email address can bypass the verification process and reset the password without providing the correct code, exposing user accounts to unauthorized access. This issue has been addressed in version 1.7.3 of the server software.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.