CVE-2024-10620

MEDIUM

Knightliao Disconf 2.6.36 - Auth Bypass

Title source: llm
STIX 2.1

Description

A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list of the component Configuration Center. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

References (5)

Core 5
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.282633
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.282633
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.429927
Issue Tracking issue-tracking
https://github.com/knightliao/disconf/issues/431

Scores

CVSS v3 5.3
EPSS 0.0050
EPSS Percentile 38.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
knightliao/Disconf 2.6.36
Published Nov 01, 2024
Tracked Since Feb 18, 2026