Incorrect Access Control in BookStack Allows DoS via Public Facing Forms
CVE-2024-36676

Currently unrated

Key Information:

Vendor

BookStack

Vendor
CVE Published:
9 July 2024

What is CVE-2024-36676?

Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms.

References

Timeline

  • Vulnerability published

.