CVE-2024-48953

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 7, 2024
Updated: Nov 8, 2024
CWE ID 306

Summary

CVE-2024-48953: A vulnerability was discovered in Logpoint versions prior to 7.5.0. The issue lies in the lack of adequate authorization checks for endpoints used to create, edit, or delete third-party authentication modules. As a consequence, unauthenticated users can register their own authentication plugins, potentially granting them unauthorized access to the system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share