CVE-2024-24761 HIGH

CVE-2024-24761: Galette public pages accessibility restriction

Vendor Galette
Product galette
Weakness CWE-863 · Incorrect authorization
Published March 6, 2024
Last update August 22, 2024

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages are per default restricted to only administrators and staff members. From configuration, it is possible to restrict to up-to-date members or to everyone. Version 1.0.2 fixes this issue.

Key dates

02Disclosure timeline

March 6, 2024 CVE published
August 22, 2024 Record updated