CVE-2024-2412
Last modified
CVE-2024-2412 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be disabled.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be disabled.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-2412?
How severe is CVE-2024-2412?
How do I fix CVE-2024-2412?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-24110SQL Injection vulnerability in crmeb_java before v1.3.4 allo…6.5
- CVE-2024-24112xmall v1.1 was discovered to contain a SQL injection vulnera…9.8
- CVE-2024-24113xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vu…8.8
- CVE-2024-24115A stored cross-site scripting (XSS) vulnerability in the Edi…5.4
- CVE-2024-24116An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(97…9.8
- CVE-2024-24117Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P R…9.8
- CVE-2024-24122A remote code execution vulnerability in the project managem…3.3
- CVE-2024-2413Intumit SmartRobot uses a fixed encryption key for authentic…9.8
- CVE-2024-24130Mail2World v12 Business Control Center was discovered to con…6.1
- CVE-2024-24131SuperWebMailer v9.31.0.01799 was discovered to contain a ref…6.1
- CVE-2024-24133Atmail v6.6.0 was discovered to contain a SQL injection vuln…9.8
- CVE-2024-24134Sourcecodester Online Food Menu 1.0 is vulnerable to Cross S…4.8
Are you affected by CVE-2024-2412?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
