← Back to CVE List

CVE-2024-6534

Published: 2024-08-15T04:15Z
Last Modified: 2024-08-19T18:17Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because the application only validates the user parameter in the 'POST /presets' request but not in the PATCH request. When chained with CVE-2024-6533, it could result in account takeover. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt