CVE-2024-25635 is a high-severity vulnerability affecting alf.io, an open-source ticket reservation system, prior to version 2.0-M4-2402. It allows authenticated organization owners to view sensitive details, including API keys and user information, of other organization owners via a specific API endpoint. With a CVSS score of 8.8, this flaw presents a significant risk of full confidentiality, integrity, and availability compromise due to its low attack complexity and network-based vector. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, suggesting it is not widely targeted at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0-m4-2402CPE matchmatch criteria | cpe:2.3:a:alf:alf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.