CVE-2024-56085

Published at:
2024-12-16T06:15:07.257

Global infos:

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

CVE Status: Awaiting Analysis

References:

  • [email protected]
  • Metrics:

    AttributeValue
    Attack ComplexityHIGH
    Attack VectorADJACENT_NETWORK
    Availability ImpactLOW
    Base Score5.9
    Base SeverityMEDIUM
    Confidentiality ImpactHIGH
    Integrity ImpactLOW
    Privileges RequiredLOW
    ScopeUNCHANGED
    User InteractionNONE
    Vector StringCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
    Exploitability Score1.2
    Impact Score4.7
    Source134c704f-9b21-4f2e-91b3-4a467353bcc0
    TypeSecondary

    Links:

    Exploit-db
    Github