CVE-2024-27295 affects Directus, a real-time API and app dashboard, through a flaw in its password reset mechanism. Attackers can exploit this by requesting a password reset for a victim, causing the email to be sent to a similar address with accented characters due to MySQL/MariaDB's default accent-insensitive comparisons. This vulnerability carries a high CVSS score of 8.2, indicating a network-based attack with low complexity that can lead to high confidentiality impact (unauthorized access to user accounts) but no integrity or availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.8.3CPE matchmatch criteria | cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.