CVE-2024-27292
HIGH 7.5EPSS 69.5%
Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS
- 69.49% chance of exploitation in the next 30 days, 99th percentile
- Nuclei
- high · CWE-706
- Published
- 2024-02-29
- Updated
- 2024-08-02
Proof-of-concept exploits (3)
- NingXin2002/Docassemble_poc3★ · 2024-12-21
- tequilasunsh1ne/CVE_2024_272920★ · 2024-07-08
- th3gokul/CVE-2024-272927★ · 2024-07-02