Description
nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://cve.naver.com/detail/cve-2024-28216.html |
|
History
Wed, 07 May 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Naver
Naver ngrinder |
|
| CPEs | cpe:2.3:a:naver:ngrinder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Naver
Naver ngrinder |
Fri, 06 Sep 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 06 Sep 2024 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 |
Mon, 12 Aug 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: naver
Published:
Updated: 2024-09-06T04:17:45.466Z
Reserved: 2024-03-07T02:38:58.221Z
Link: CVE-2024-28216
Updated: 2024-08-02T00:48:49.603Z
Status : Analyzed
Published: 2024-03-07T05:15:55.063
Modified: 2025-05-07T15:30:48.877
Link: CVE-2024-28216
No data.
OpenCVE Enrichment
No data.
Weaknesses