CVE-2024-56087

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:logpoint:siem:*:*:*:*:*:*:*:*

History

17 Apr 2025, 01:50

Type Values Removed Values Added
CPE cpe:2.3:a:logpoint:siem:*:*:*:*:*:*:*:*
First Time Logpoint
Logpoint siem
References () https://servicedesk.logpoint.com/hc/en-us/articles/22137697881885-Server-Side-Template-Injection-SSTI-in-Search-Template-Dashboard-Queries - () https://servicedesk.logpoint.com/hc/en-us/articles/22137697881885-Server-Side-Template-Injection-SSTI-in-Search-Template-Dashboard-Queries - Vendor Advisory
Summary
  • (es) Se descubrió un problema en Logpoint antes de la versión 7.5.0. Los usuarios autenticados pueden inyectar payloads mientras consultan el Panel de plantillas de búsqueda. Estas se ejecutan, lo que genera Server-Side Template Injection.

16 Dec 2024, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CWE CWE-77

16 Dec 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-16 06:15

Updated : 2025-04-17 01:50


NVD link : CVE-2024-56087

Mitre link : CVE-2024-56087

CVE.ORG link : CVE-2024-56087


JSON object : View

Products Affected

logpoint

  • siem
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')