Record summary

CVE-2024-6695 has a selected CVSS score of 9.8 (critical).

Description

it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 23, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

User Profile Builder

Default status: unaffected

CVE ListBefore 3.11.9affected

Default status: unaffected

CVE List, VulnCheckBefore 3.11.9affected

References

2