CVE-2024-27292
Dashboard / Vulnerabilities / CVE-2024-27292
CVE-2024-27292
Summary: Docassemble unauthorized access through URL manipulation
Details: Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27292.json, https://github.com/jhpyle/docassemble/security/advisories/GHSA-jq57-3w7p-vwvv, https://nvd.nist.gov/vuln/detail/CVE-2024-27292, https://github.com/jhpyle/docassemble/commit/97f77dc486a26a22ba804765bfd7058aabd600c9
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
