CVE Feed

    Dashboard / CVE / CVE-2024-47768

    CVE-2024-47768

    Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct code. If the attacker knew the email of the target, they could supply the email and immediately prompt the server to update the password without ever needing the code. This issue has been patched in version 1.7.3.

    Published:Oct 4, 2024
    Last Modified:Nov 13, 2024
    EPS:Oct 4, 2024
    EPSS Score:0.00185
    CVSS Score:8.1

    Affected Products

    Vendor
    Lifplatforms
    Product
    Lif Authentication Server

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High