PT-2024-33151 · Aquilacms · Aquilacms

Dos-M0Nk3Y

·

Published

2024-10-29

·

Updated

2024-11-01

·

CVE-2024-48572

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions AquilaCMS versions 1.409.20 and prior
Description The issue arises from insufficient validation of user input, which is processed as a regular expression to find duplicate email addresses via the "Add a user" feature, allowing unauthenticated attackers to obtain email addresses.
Recommendations For versions 1.409.20 and prior, as a temporary workaround, consider restricting access to the "Add a user" feature until a patch is available. Additionally, ensure that user input is thoroughly validated to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-48572

Affected Products

Aquilacms