Incorrect Access Control in BookStack Allows DoS via Public Facing Forms
CVE-2024-36676
7.5HIGH
What is CVE-2024-36676?
An access control vulnerability exists in BookStack prior to version 24.05.1, enabling malicious actors to confirm the existence of users within the system. This exploit can be leveraged through public-facing forms to launch targeted notification email denial-of-service attacks, potentially disrupting user communication and service functionality.
