CVE-2024-47768

HIGH

Lif Authentication Server <1.7.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct code. If the attacker knew the email of the target, they could supply the email and immediately prompt the server to update the password without ever needing the code. This issue has been patched in version 1.7.3.

Scores

CVSS v3 8.1
EPSS 0.0043
EPSS Percentile 62.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862 CWE-287
Status published
Products (1)
lifplatforms/lif_authentication_server < 1.7.3
Published Oct 04, 2024
Tracked Since Feb 18, 2026