CVE-2024-48950

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
07/11/2024
Last modified:
18/04/2025

Description

An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:logpoint:siem:*:*:*:*:*:*:*:* 7.5.0 (excluding)