CVE-2024-57190: Erxes
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.
Affected products
- Erxes Erxes: before 1.6.1 (fixed in 1.6.1)
Published 2025-06-10. Last modified 2026-06-17.