CVE-2024-47768

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Oct 4, 2024
Updated: Nov 13, 2024
CWE ID 287
CWE ID 862

Summary

CVE-2024-47768 is a vulnerability affecting Lif Authentication Server, used by Lif for account-related tasks. The account recovery system, which allows users to regain access to their accounts if they have lost or forgotten their passwords, does not include adequate checks. An attacker who knows a target's email address can bypass the verification process and reset the password without providing the correct code, exposing user accounts to unauthorized access. This issue has been addressed in version 1.7.3 of the server software.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share