nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6695 CVE-2024-6695
CRITICAL
profile-builder <= 3.11.8 - Unauthenticated Privilege Escalation
Record summary
CVE-2024-6695 has a selected CVSS score of 9.8 (critical).
Description
it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 23, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
User Profile BuilderDefault status: unaffected | CVE List | Before 3.11.9 | affected |
profile_builderBrowse cozmoslabs / profile_builderDefault status: unaffected | CVE List, VulnCheck | Before 3.11.9 | affected |
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/4afa5c85-ce27-4ca7-bba2-61fb39c53a5b