CVE-2024-2412: Heimavista Epage

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be disabled.

Affected products

  • Heimavista Epage: up to and including 3.0.106.20231112
  • Heimavista Rpage: up to and including 5.4.103.20231111

Published 2024-03-13. Last modified 2026-06-17.