CVE-2024-6695: profile-builder <= 3.11.8 - Unauthenticated Privilege Escalation
Published Jul 31, 2024
·Updated
it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.
Affected Software
2 affected components
Profile Builder Profile Builder<=3.11.8
Cozmoslabs Profile Builder Wordpress<3.11.9
Event History
Jul 31, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-6695?
CVE-2024-6695 has been classified as a high severity vulnerability due to potential unauthorized administrative access.
2
How do I fix CVE-2024-6695?
To fix CVE-2024-6695, you should update Profile Builder to version 3.11.9 or later.
3
What is the impact of CVE-2024-6695?
The impact of CVE-2024-6695 allows attackers to perform unauthorized actions by gaining administrative access without an account.
4
What versions of Profile Builder are affected by CVE-2024-6695?
Profile Builder versions up to and including 3.11.8 are affected by CVE-2024-6695.
5
Can CVE-2024-6695 be exploited remotely?
Yes, CVE-2024-6695 can be exploited remotely by attackers targeting the vulnerable user registration process.