Vulnerabilities
23 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-66360 | An issue was discovered in Logpoint before 7.7.0. An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) information to li-admin users. This can lead to privilege escalation. NVD description · AI analysis pending | 6.9 group max | <1% |
| — | ||
| CVE-2024-56086 | An issue was discovered in Logpoint before 7.5.0. An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution. NVD description · AI analysis pending | 7.1 group max | <1% |
| — | ||
| CVE-2024-56084 | An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution. NVD description · AI analysis pending | 7.1 | <1% |
| — | ||
| CVE-2024-48950 | An issue was discovered in Logpoint before 7.5.0. An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and authentication. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2024-48952 | An issue was discovered in Logpoint before 7.5.0. An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints. NVD description · AI analysis pending | 6.4 | <1% |
| — | ||
| CVE-2024-36383 | An issue was discovered in Logpoint SAML Authentication before 6.0.3. An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the state field of a SAML SSO-URL response, and the file corresponding to this filename will ultimately be deleted. This can lead to a SAML Authentication login outage. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2024-33857 | An issue was discovered in Logpoint before 7.4.0. An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access to the system can trigger Server Side Request Forgery. NVD description · AI analysis pending | 9.6 group max | <1% |
| — | ||
| CVE-2024-30176 | In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets. In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2022-48684 +1 in the same advisory: …48685 | An issue was discovered in Logpoint before 7.1.1. An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jinja templating for generating dynamic data. This could be abused to achieve code execution. Any user with access to create a search template can leverage this to execute code as the loginspect user. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2024-29865 | Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form. Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2023-49950 | The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template in The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template in the Alert view. A remote attacker can craft a cross-site scripting (XSS) payload and send it to any system or device that sends logs to the SIEM. If an alert is created, the payload will execute upon the alert data being viewed with that template, which can lead to sensitive data disclosure. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — |