V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-30614
CVE
MediumConfirmedExploit available

An issue in Ametys CMS v4.5.0 and before allows attackers to obtain sensitive information via exposed resources to the error scope.

CVSS
5.3
Medium
EPSS
0.00
p37
Published
2024-01-01
Updated
2024-01-01
Description

An issue in Ametys CMS v4.5.0 and before allows attackers to obtain sensitive information via exposed resources to the error scope.

Tags · CWE
Pre-auth
CWE-209
CAPEC-7
CAPEC-54
CAPEC-215
CAPEC-463
Affected products
Ametys ≤ 4.5.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.005 · p37
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2024-30614
github-poc · https://github.com/Lucky-lm/CVE-2024-30614
Enterprise
Affected products
ProductVendorStatus
ametys*Tracked
Source databases
CVE