CVE-2024-28215

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/03/2024
Last modified:
07/05/2025

Description

nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:naver:ngrinder:*:*:*:*:*:*:*:* 3.5.9 (excluding)