CVE-2024-4447
Last modified
CVE-2024-4447 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting API (UserSessionAjax.getSessionList.dwr) calls. While this is information that would and should be available to admins who possess "Sign In As" powers, admins who otherwise lack this privilege would still be able to utilize the session IDs to imitate other users. While this is a very small attack vector that requires very high permissions to execute, its danger lies principally in obfuscating attribution; all Sign In As operations are attributed appropriately in the log files, and a malicious administrator could use this information to render their dealings untraceable — including those admins who have not been granted this ability — such as by using a session ID to generate an API token. Fixed in: 24.07.12 / 23.01.20 LTS / 23.10.24v13 LTS / 24.04.24v5 LTS This was the original found by researcher Zakaria Agharghar. 2. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting API (UserSessionAjax.getSessionList.dwr) calls. While this is information that would and should be available to admins who possess "Sign In As" powers, admins who otherwise lack this privilege would still be able to utilize the session IDs to imitate other users. While this is a very small attack vector that requires very high permissions to execute, its danger lies principally in obfuscating attribution; all Sign In As operations are attributed appropriately in the log files, and a malicious administrator could use this information to render their dealings untraceable — including those admins who have not been granted this ability — such as by using a session ID to generate an API token. Fixed in: 24.07.12 / 23.01.20 LTS / 23.10.24v13 LTS / 24.04.24v5 LTS This was the original found by researcher Zakaria Agharghar. 2. Later, on October 20, 2025, another researcher (Chris O’Neill) found additional affected DWR Endpoints that are vulnerable to Information Disclosure, namely and in addition to the original found of "UserSessionAjax.getSessionList.dwr - Session ID exposure": * UserAjax.getUsersList.dwr - Enumerate all users with IDs, names, emails * RoleAjax.getUserRole.dwr - Get user role information * RoleAjax.getRole.dwr - Get role details * RoleAjax.getRolePermissions.dwr - View role permissions * RoleAjax.isPermissionableInheriting.dwr - Check permission inheritance * RoleAjax.getCurrentCascadePermissionsJobs.dwr - View permission cascade jobs * ThreadMonitorTool.getThreads.dwr - Monitor system threads; and, * CRITICAL - Privilege Escalation: RoleAjax.saveRolePermission.dwr - Modify role permissions Overall CVSS for the above findings: * CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L * Score: 9.1 (Critical)
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-4447?
How severe is CVE-2024-4447?
How do I fix CVE-2024-4447?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-4445The WP Compress – Image Optimizer [All-In-One] plugin for Wo…4.3
- CVE-2024-44450Multiple functions are vulnerable to Authorization Bypass in…5.4
- CVE-2024-44459A memory allocation issue in vernemq v2.0.1 allows attackers…7.5
- CVE-2024-4446The Content Views – Post Grid & Filter, Recent Posts, Catego…6.4
- CVE-2024-44460An invalid read size in Nanomq v0.21.9 allows attackers to c…7.5
- CVE-2024-44466COMFAST CF-XR11 V2.7.2 has a command injection vulnerability…9.8
- CVE-2024-4448The Essential Addons for Elementor – Best Elementor Template…6.4
- CVE-2024-4449The Essential Addons for Elementor – Best Elementor Template…5.4
- CVE-2024-4450The AliExpress Dropshipping with AliNext Lite plugin for Wor…6.3
- CVE-2024-4451The Colibri Page Builder plugin for WordPress is vulnerable …5.4
- CVE-2024-4452The ElementsKit Pro plugin for WordPress is vulnerable to St…5.4
- CVE-2024-4453GStreamer EXIF Metadata Parsing Integer Overflow Remote Code…7.8
Are you affected by CVE-2024-4447?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
