Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jq57-3w7p-vwvv | Docassemble unauthorized access through URL manipulation |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 02 Sep 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jhpyle
Jhpyle docassemble |
|
| CPEs | cpe:2.3:a:jhpyle:docassemble:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jhpyle
Jhpyle docassemble |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T19:27:42.423Z
Reserved: 2024-02-22T18:08:38.874Z
Link: CVE-2024-27292
Updated: 2024-08-02T00:27:59.932Z
Status : Analyzed
Published: 2024-03-21T02:52:19.560
Modified: 2025-09-02T13:37:21.560
Link: CVE-2024-27292
No data.
OpenCVE Enrichment
No data.
Github GHSA