CVE-2024-40407
HIGHDescription
A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.
Is your site exposed to CVE-2024-40407?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| cybelesoft | thinfinity_workspace |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-40407? +
How severe is CVE-2024-40407? +
What products are affected by CVE-2024-40407? +
How do I check if I'm vulnerable to CVE-2024-40407? +
Related Vulnerabilities
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web …
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via …
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This …
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.