Sploitus

CVE-2024-6534

No indexed exploits for CVE-2024-6534 yet

Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because the application only validates the user parameter in the 'POST /presets' request but not in the PATCH request. When chained with CVE-2024-6533, it could result in account takeover.

Affected products
Directus
Monospace Directus
= 10.13.0
CVSS 3.1
4.3 MEDIUM
EPSS
0.3% (25th percentile)
Weakness
CWE-639
NVD status
Modified
Published
2024-08-15
Attack patterns
CAPEC-180
CVE-2024-6534 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-6534 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-6534 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.