CVE-2024-10267: Information Disclosure in transformeroptimus/superagi
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by attempting to register a new account with an email that is already in use. The server returns all information associated with the existing account. The vulnerable endpoint is located in the user registration functionality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10267?
CVE-2024-10267 is classified as an information disclosure vulnerability that can lead to the leakage of sensitive user information.
How do I fix CVE-2024-10267?
To fix CVE-2024-10267, implement input validation to ensure that the server does not disclose user information through error messages.
What kind of information can be leaked due to CVE-2024-10267?
CVE-2024-10267 allows an attacker to leak sensitive user information, including names, emails, and passwords.
Is my software affected by CVE-2024-10267?
CVE-2024-10267 affects the latest version of transformeroptimus/superagi software.
What should I do if my email is already in use on transformeroptimus/superagi?
If your email is already in use, avoid attempting to register again and ensure that security measures are in place to protect your information.