CVE-2024-36676
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
09/07/2024
Last modified:
11/07/2024
Description
Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



