CVE-2024-51992

CVSS 3.1 Score 4.1 of 10 (medium)

Details

Published Nov 11, 2024
Updated: Nov 12, 2024
CWE ID 749

Summary

CVE-2024-51992: A method exposure issue (CWE-749) was discovered in Orchid, a popular Laravel package used for back-end application development. Affecting Orchid Platform versions 8 through 14.42.x, this vulnerability exposes the Orchid Platform's asynchronous modal functionality to arbitrary method calls within the `Screen` class. Potential consequences include database table brute force, user credential validation checks, and disclosure of the server's real IP address. Users are advised to upgrade to the latest version, 14.43.0, released on November 6, 2024, to mitigate this risk. Alternatively, implementing middleware to validate and approve only authorized methods and parameters can help mitigate the vulnerability until upgrading is possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share