Plaintext Password Exposure in SuperAGI by TransformerOptimus
CVE-2024-9418
6.5MEDIUM
What is CVE-2024-9418?
In version 0.0.14 of SuperAGI by TransformerOptimus, a vulnerability exists in the /api/users/get/{id} endpoint where it exposes user passwords in plaintext. This significant oversight enables attackers to gain unauthorized access to sensitive user information, increasing the risk of account takeover incidents. The flaw highlights the necessity for robust security measures in API design to safeguard user credentials against exploitation.
Affected Version(s)
transformeroptimus/superagi <= unspecified
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
