CVE-2024-25635
HIGHDescription
alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the generated API KEY and USERS of other organization owners using the `http://192.168.26.128:8080/admin/api/users/<user_id>` endpoint, which exposes the details of the provided user ID. This may also expose the API KEY in the username of the user. Version 2.0-M4-2402 fixes this issue.
Is your site exposed to CVE-2024-25635?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| alf | alf |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-25635? +
How severe is CVE-2024-25635? +
What products are affected by CVE-2024-25635? +
How do I check if I'm vulnerable to CVE-2024-25635? +
Related Vulnerabilities
Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized …
Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content …
Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access the …
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, a …
alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other organizers. …
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the …