CVE-2024-23734: Savignano S-Notify
Medium severity, CVSS 5.2. EPSS: 0.1% chance of exploitation in the next 30 days.
Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link.
Affected products
- Savignano S-Notify: before 2.0.1 (fixed in 2.0.1)
Published 2024-04-10. Last modified 2026-06-17.