CVE-2024-36070

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authentication information via setup.php because of getRegistryData in Setup/Frontend/Json.php. (An update is also available for the 2022.11 series.)

Published 2024-05-19. Last modified 2026-06-17.