PT-2023-27927 · Cerebrate · Cerebrate

CVE-2023-41363

·

Publicado

2023-08-28

·

Atualizado

2023-08-31

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cerebrate version 1.14
Description A vulnerability in the UserSettingsController allows authenticated users to change user settings of other users.
Recommendations For Cerebrate version 1.14, consider restricting access to the UserSettingsController until a patch is available. As a temporary workaround, limit the ability of authenticated users to modify user settings to prevent unauthorized changes.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-41363

Produtos afetados

Cerebrate