VulnerabilityAnalyzed
CVE-2024-24761
Galette is a membership management web application for non profit organizations.
HIGH 7.5EPSS 0.61%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages are per default restricted to only administrators and staff members. From configuration, it is possible to restrict to up-to-date members or to everyone. Version 1.0.2 fixes this issue.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.61% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- galette/galette
- Source
- security-advisories@github.com
References
- https://github.com/galette/galette/commit/a5c18bb9819b8da1b3ef58f3e79577083c657fbbPatch
- https://github.com/galette/galette/security/advisories/GHSA-jrqg-mpwv-pxpvVendor Advisory
- https://github.com/galette/galette/commit/a5c18bb9819b8da1b3ef58f3e79577083c657fbbPatch
- https://github.com/galette/galette/security/advisories/GHSA-jrqg-mpwv-pxpvVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.