CVE-2024-9000

CVSS v3 Score
7.1
High

Vulnerability Description

In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the user has proper permissions. This missing access control permits unauthorized users to create checklists, bypassing intended permission checks. Additionally, the endpoint does not validate the uniqueness of the slug field when creating a new checklist, allowing an attacker to spoof existing checklists by reusing the slug of an already-existing checklist. This can lead to significant data integrity issues, as legitimate checklists can be replaced with malicious or altered data.

CVSS:7.1(High)

After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts re...

CVSS:7.1(High)

A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VM...

CVSS:7.1(High)

Using empty PendingIntent in Galaxy Themes prior to version 5.2.00.1215 allows local attackers to read/write private file directories of Galaxy Themes application without permission via hijacking the ...

CVSS:7.1(High)

Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.

CVSS:7.1(High)

Improper Authorization in Packagist librenms/librenms prior to 22.2.0.

CVSS:7.1(High)

Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.