PT-2024-33490 · Autolab · Autolab
Henryhuang2004
·
Published
2024-10-25
·
Updated
2024-11-14
·
CVE-2024-49376
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Autolab version 3.0.0
Description
The issue concerns misconfigured reset password permissions for email-based accounts. Users with insufficient privileges could reset and potentially access privileged users' accounts by resetting their passwords.
Recommendations
For version 3.0.0, update to version 3.0.1 to resolve the issue. As a temporary workaround, consider restricting access to the password reset feature until the update is applied.
Exploit
Fix
Incorrect Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Autolab