CVE-2024-49376 is a critical misconfiguration vulnerability in Autolab version 3.0.0, a course management service, allowing users with insufficient privileges to reset and potentially access privileged user accounts. This high-severity flaw, rated 8.8 CVSS, is easily exploitable over the network with low attack complexity, posing a significant risk of unauthorized access, data compromise, and service disruption. While no active exploitation, public exploit code, or significant community discussion has been observed, immediate patching to version 3.0.1 is crucial as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0CPE matchmatch criteria | cpe:2.3:a:autolabproject:autolab:3.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.