CVE-2024-27292 is a high-severity local file inclusion vulnerability in Docassemble versions 1.4.53 through 1.4.96, allowing unauthorized information access through URL manipulation. With a CVSS score of 7.5 (HIGH) and an EPSS score indicating high exploitability, this flaw poses a significant risk due to its low attack complexity and potential for complete confidentiality compromise. While not yet on the KEV catalog, a Nuclei template for exploitation exists, and despite a lack of broader community discussion or media coverage, the high FAUCET Risk Score of 99/100 underscores its critical nature. The vulnerability has been patched in Docassemble version 1.4.97.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4.53, < 1.4.97CPE matchmatch criteria | cpe:2.3:a:jhpyle:docassemble:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.