CVE-2024-37767: b1ackc4t 14finger
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.
Affected products
- b1ackc4t 14finger: version 1.1 only
Published 2024-07-05. Last modified 2026-06-17.