CVE-2024-40530: Uab Lexita Panteracrm CMS

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access controls by manipulating the X-Forwarded-For header.

Affected products

Published 2024-08-05. Last modified 2026-06-17.