PT-2024-27739 · 14Finger · 14Finger

·

CVE-2024-37768

·

Published

2024-07-05

·

Updated

2024-07-08

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions 14Finger version 1.1
Description The issue allows for arbitrary user deletion through the "/api/admin/user?id" API endpoint. This endpoint is used for administrative purposes, and the vulnerability could be exploited to delete users without proper authorization.
Recommendations For version 1.1, consider disabling access to the "/api/admin/user?id" API endpoint until a patch is available to prevent exploitation. Restricting the use of the id parameter in this endpoint can also help minimize the risk.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-37768

Affected Products

14Finger