← Back

CVE-2024-6534

nvd nist
Published: Aug 15, 2024Modified: May 19, 2025

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD (Secondary)

Description

Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because the application only validates the user parameter in the 'POST /presets' request but not in the PATCH request. When chained with CVE-2024-6533, it could result in account takeover.

Affected (1)

Products: Monospace: Directus
1 product
Directus
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.13.0

References (2)

Source: help@fluidattacks.com
Product
Source: help@fluidattacks.com
Third Party Advisory

Timeline

No history available yet.