← back
CVE-2024-27292highobserved exploitationCWE-706

Docassemble unauthorized access through URL manipulation

90Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 7.5epss 69%
from disclosure to weapon124 days
Published on NVDFeb 29
1st PoC+124d
VulnCheck+464d
exploitation probability
69%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
jhpyle · docassemble
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.