CVE-2024-55963
CVE-2024-55963
Vexday Risk Score
38Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 6.5EPSS 25.0%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
26 Mar 2025Published on NVD
03 Apr 2025Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
n/a · n/apublic PoCs found — 2
githubgithub.com/superswan/CVE-2024-55963★ 2exploitdbwww.exploit-db.com/exploits/52118unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →