PT-2024-20539 · Galette · Galette

·

CVE-2024-24761

·

Published

2024-03-06

·

Updated

2024-12-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Galette versions 1.0.0 through 1.0.1
Description Galette is a membership management web application for non-profit organizations. By default, public pages are restricted to only administrators and staff members in versions prior to 1.0.2. Configuration options allow for restriction to up-to-date members or to everyone.
Recommendations For versions 1.0.0 through 1.0.1, update to version 1.0.2 to resolve the issue.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-24761
GHSA-JRQG-MPWV-PXPV

Affected Products

Galette