Xibo Digital Signage Platform Vulnerability Affects Sessions
CVE-2024-29023
What is CVE-2024-29023?
The Xibo Digital Signage platform has a vulnerability that exposes session tokens in the response from the session search API on the sessions page. This flaw allows unauthorized access if a user gains access to the session page and can lead to session hijacking. Users should ensure they are running the updated versions (3.3.10 or 4.0.9) to mitigate this security risk. Customers using the Xibo Signage service have already received necessary updates, while patches are available for unsupported earlier versions. No workarounds exist, making it crucial for users to apply the recommended upgrades immediately.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
xibo-cms >= 1.8.0, < 3.3.10 < 1.8.0, 3.3.10
xibo-cms >= 4.0.0, < 4.0.9 < 4.0.0, 4.0.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
