CVE-2024-6534 is a medium-severity vulnerability affecting Directus v10.13.0, allowing an authenticated attacker to modify their own user presets and assign them to another user due to insufficient validation in PATCH requests. The CVSS score is 4.3, indicating a low attack complexity and impact limited to data integrity. While not actively exploited or having public exploit code, this vulnerability could contribute to account takeover when chained with CVE-2024-6533. There is currently no community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.13.0CPE matchmatch criteria | cpe:2.3:a:monospace:directus:10.13.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.