Vulnerabilities > CVE-2024-24761 - Incorrect Authorization vulnerability in Galette 1.0.0/1.0.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
galette
CWE-863

Summary

Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages are per default restricted to only administrators and staff members. From configuration, it is possible to restrict to up-to-date members or to everyone. Version 1.0.2 fixes this issue.

Vulnerable Configurations

Part Description Count
Application
Galette
2

Common Weakness Enumeration (CWE)