CVE-2024-6534
Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because the application only validates the user parameter in the 'POST /presets'Â request but not in the PATCH request. When chained with CVE-2024-6533, it could result in account takeover.
- Affected products
- Directus
- Monospace Directus
- = 10.13.0
- CVSS 3.1
- 4.3 MEDIUM
- EPSS
- 0.3% (25th percentile)
- Weakness
- CWE-639
- NVD status
- Modified
- Published
- 2024-08-15
- Attack patterns
- CAPEC-180
CVE-2024-6534 at NVD
No indexed exploits for CVE-2024-6534 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-6534 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.