CVE-2024-56085

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:logpoint:siem:*:*:*:*:*:*:*:*

History

17 Apr 2025, 01:48

Type Values Removed Values Added
CPE cpe:2.3:a:logpoint:siem:*:*:*:*:*:*:*:*
References () https://servicedesk.logpoint.com/hc/en-us/articles/22137660393757-Server-Side-Template-Injection-SSTI-in-Search-Template-Dashboard - () https://servicedesk.logpoint.com/hc/en-us/articles/22137660393757-Server-Side-Template-Injection-SSTI-in-Search-Template-Dashboard - Vendor Advisory
First Time Logpoint
Logpoint siem
Summary
  • (es) Se descubrió un problema en Logpoint antes de la versión 7.5.0. Los usuarios autenticados pueden inyectar payloads mientras crean el Panel de plantillas de búsqueda. Estas se ejecutan, lo que genera Server-Side Template Injection.

16 Dec 2024, 16:15

Type Values Removed Values Added
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9

16 Dec 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-16 06:15

Updated : 2025-04-17 01:48


NVD link : CVE-2024-56085

Mitre link : CVE-2024-56085

CVE.ORG link : CVE-2024-56085


JSON object : View

Products Affected

logpoint

  • siem
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')