CVE-2024-23734: Savignano S-Notify

Medium severity, CVSS 5.2. EPSS: 0.1% chance of exploitation in the next 30 days.

Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link.

Affected products

  • Savignano S-Notify: before 2.0.1 (fixed in 2.0.1)

Published 2024-04-10. Last modified 2026-06-17.