CVE-2024-36676

HIGH8.2EPSS 0.23%

BookStack Incorrect Access Control vulnerability

Published: 7/10/2024Modified: 7/11/2024
Also known as:GHSA-pj36-fcrg-327j

Description

Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
osvCVSS 3.1HIGH8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

References (6)