Xibo Digital Signage Platform Vulnerability Affects Sessions
CVE-2024-29023

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
12 April 2024

What is CVE-2024-29023?

The Xibo Digital Signage platform has a vulnerability that exposes session tokens in the response from the session search API on the sessions page. This flaw allows unauthorized access if a user gains access to the session page and can lead to session hijacking. Users should ensure they are running the updated versions (3.3.10 or 4.0.9) to mitigate this security risk. Customers using the Xibo Signage service have already received necessary updates, while patches are available for unsupported earlier versions. No workarounds exist, making it crucial for users to apply the recommended upgrades immediately.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

xibo-cms >= 1.8.0, < 3.3.10 < 1.8.0, 3.3.10

xibo-cms >= 4.0.0, < 4.0.9 < 4.0.0, 4.0.9

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.