lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFirstName function using a different whitespace character (e.g., \xa0). This vulnerability can be exploited to conduct phishing attacks, damage the application's brand, cause legal and compliance issues, and result in financial impact due to unauthorized email usage.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lunary
Lunary lunary |
|
Weaknesses | CWE-74 | |
CPEs | cpe:2.3:a:lunary:lunary:1.2.26:*:*:*:*:*:*:* | |
Vendors & Products |
Lunary
Lunary lunary |
|
Metrics |
cvssV3_1
|
Tue, 29 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lunary-ai
Lunary-ai lunary |
|
CPEs | cpe:2.3:a:lunary-ai:lunary:*:*:*:*:*:*:*:* | |
Vendors & Products |
Lunary-ai
Lunary-ai lunary |
|
Metrics |
ssvc
|
Tue, 29 Oct 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFirstName function using a different whitespace character (e.g., \xa0). This vulnerability can be exploited to conduct phishing attacks, damage the application's brand, cause legal and compliance issues, and result in financial impact due to unauthorized email usage. | |
Title | Email Injection Vulnerability in lunary-ai/lunary | |
Weaknesses | CWE-75 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-10-29T12:49:50.701Z
Updated: 2024-10-29T18:15:43.860Z
Reserved: 2024-08-04T13:38:41.689Z
Link: CVE-2024-7472
Vulnrichment
Updated: 2024-10-29T18:15:38.139Z
NVD
Status : Analyzed
Published: 2024-10-29T13:15:09.093
Modified: 2024-10-31T18:46:32.497
Link: CVE-2024-7472
Redhat
No data.