CVE-2024-36676

Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms.
Configurations

No configuration.

History

No history.

Information

Published : 2024-07-09 22:15

Updated : 2024-07-11 15:05


NVD link : CVE-2024-36676

Mitre link : CVE-2024-36676

CVE.ORG link : CVE-2024-36676


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')