CVE-2024-27631
published 2024-04-08CVE-2024-27631: Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php
PriorityP430medium6CVSS 3.1
AVNACLPRHUINSUCHILAL
EPSS
0.42%
33.9th percentile
Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | savane | < 3.13 | 3.13 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.savannah.nongnu.org/cgit/administration/savane.git/commit/?h=i18n&id=d3962d3feb75467489b869204db98e2dffaaaf09https://github.com/ally-petitt/CVE-2024-27631https://medium.com/%40allypetitt/how-i-found-3-cves-in-2-days-8a135eb924d3https://git.savannah.nongnu.org/cgit/administration/savane.git/commit/?h=i18n&id=d3962d3feb75467489b869204db98e2dffaaaf09https://github.com/ally-petitt/CVE-2024-27631https://medium.com/%40allypetitt/how-i-found-3-cves-in-2-days-8a135eb924d3
2024-04-08
Published