CVE-2024-52294
CVE-2024-52294 is an Insecure Direct Object Reference (IDOR) vulnerability affecting the Khoj AI app. This flaw allows authenticated users to modify other users' Stripe subscriptions by manipulating the email parameter. The vulnerability exists in the /api/subscription
endpoint because it lacks authorization checks to verify subscription ownership. Even though authentication is needed, a malicious user can update any subscription by simply changing the email in the request, highlighting a serious access control issue. The SVRS score of 38 indicates a moderate risk, suggesting the vulnerability is exploitable but not considered critical based on SOCRadar's metrics. This issue was addressed in Khoj version 1.29.10 by deprecating support for arbitrary email updates, emphasizing the importance of timely patching to mitigate potential financial and data security risks. Organizations using Khoj should prioritize updating to the latest version to protect user subscription data.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.