CVE Feed

    Dashboard / CVE / CVE-2024-12869

    CVE-2024-12869

    In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite list, could be exposed without their consent. This data leakage can facilitate further attacks, such as phishing or spam, and result in loss of trust and potential regulatory issues.

    Published:Mar 20, 2025
    Last Modified:Oct 15, 2025
    EPS:Mar 20, 2025
    EPSS Score:0.00043
    CVSS Score:4.3

    Affected Products

    Vendor
    Infiniflow
    Product
    Ragflow

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High