CVE-2024-48428
CRITICALCVSS 9.8/10EPSS 0.74%
Last modified
CVE-2024-48428 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.. EPSS estimates a 0.74% chance of exploitation in the next 30 days.
Description
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Olivegroup | Olivevle | All versions |
References
- https://medium.com/%40powerful-/account-takeover-ato-via-the-reset-password-cve-2024-48428-84892d6211d6Exploit, Third Party Advisory
- https://www.olivevle.com/Product
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-48428?
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
How severe is CVE-2024-48428?
CVE-2024-48428 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.74% probability of exploitation in the next 30 days.
How do I fix CVE-2024-48428?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-48420Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vul…8.8
- CVE-2024-48423An issue in assimp v.5.4.3 allows a local attacker to execut…7.8
- CVE-2024-48424A heap-buffer-overflow vulnerability has been identified in …5.5
- CVE-2024-48425A segmentation fault (SEGV) was detected in the Assimp::Spli…5.5
- CVE-2024-48426A segmentation fault (SEGV) was detected in the SortByPTypeP…6.2
- CVE-2024-48427A SQL injection vulnerability in Sourcecodester Packers and …8.8
- CVE-2024-4843ePO doesn't allow a regular privileged user to delete tasks …4.3
- CVE-2024-4844Hardcoded credentials vulnerability in Trellix ePolicy Orche…7.5
- CVE-2024-48440Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router…8.8
- CVE-2024-48441Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router…8.8
- CVE-2024-48442Incorrect access control in Shenzhen Tuoshi Network Communic…6.5
- CVE-2024-48445An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote at…9.8
Are you affected by CVE-2024-48428?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
