CVE-2024-7472

lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFirstName function using a different whitespace character (e.g., \xa0). This vulnerability can be exploited to conduct phishing attacks, damage the application's brand, cause legal and compliance issues, and result in financial impact due to unauthorized email usage.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lunary:lunary:1.2.26:*:*:*:*:*:*:*

History

31 Oct 2024, 18:46

Type Values Removed Values Added
Summary
  • (es) lunary-ai/lunary v1.2.26 contiene una vulnerabilidad de inyección de correo electrónico en la API de verificación de envío de correo electrónico (/v1/users/send-verification) y la API de registro (/auth/signup). Un atacante no autenticado puede inyectar datos en los correos electrónicos salientes al omitir la función extractFirstName utilizando un carácter de espacio en blanco diferente (por ejemplo, \xa0). Esta vulnerabilidad se puede explotar para realizar ataques de phishing, dañar la marca de la aplicación, causar problemas legales y de cumplimiento y generar un impacto financiero debido al uso no autorizado del correo electrónico.
References () https://github.com/lunary-ai/lunary/commit/a39837d7c49936a0c435d241f37ca2ea7904d2cd - () https://github.com/lunary-ai/lunary/commit/a39837d7c49936a0c435d241f37ca2ea7904d2cd - Patch
References () https://huntr.com/bounties/dc1feec6-1efb-4538-9b56-ab25deb80948 - () https://huntr.com/bounties/dc1feec6-1efb-4538-9b56-ab25deb80948 - Exploit, Third Party Advisory
First Time Lunary
Lunary lunary
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:lunary:lunary:1.2.26:*:*:*:*:*:*:*
CWE CWE-74

29 Oct 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 13:15

Updated : 2024-10-31 18:46


NVD link : CVE-2024-7472

Mitre link : CVE-2024-7472

CVE.ORG link : CVE-2024-7472


JSON object : View

Products Affected

lunary

  • lunary
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-75

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)