Docassemble unauthorized access through URL manipulation
90Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 7.5epss 69%
from disclosure to weapon124 days
Published on NVDFeb 29
1st PoC+124d
VulnCheck+464d
exploitation probability
69%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
jhpyle · docassemblepublic PoCs found — 2
vulncheckvulncheck.com/xdb/3696c528dba3unverifiedvulncheckvulncheck.com/xdb/1b640afe406dunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.