CVE-2024-6425: Mesbook
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can register user accounts without being authenticated from the route "/account/Register/" and in the parameters "UserName=<RANDOMUSER>&Password=<PASSWORD>&ConfirmPassword=<PASSWORD-REPEAT>".
Affected products
- Mesbook Mesbook: version 20221021.03 only
Published 2024-07-01. Last modified 2026-06-17.