Improper access control in Directus - CVE-2024-27295
Published: March 1, 2024 / Updated: April 23, 2026
Directus
Directus
Description
The vulnerability allows a remote attacker to gain unauthorized access to another user's account.
The vulnerability exists due to improper access control in the password reset mechanism when handling password reset requests with accent-confusable email addresses under accent-insensitive MySQL or MariaDB comparisons. A remote attacker can submit a crafted password reset request to gain unauthorized access to another user's account.
Exploitation requires knowledge of the victim's email address and control of a similar email address that differs by accented characters.