PT-2025-9846 · Unknown · Peppermint Ticket Management

Publicado

2025-03-05

·

Atualizado

2025-03-07

·

CVE-2024-31525

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Peppermint Ticket Management version 0.4.6
Description The issue concerns Incorrect Access Control, where a regular registered user can elevate their privileges to admin and gain complete access to the system. This occurs because the authorization mechanism is not validated on the server side, but only on the client side. As a result, an attacker can create a new admin user in the system, enabling persistent access as an administrator.
Recommendations For Peppermint Ticket Management version 0.4.6, consider disabling the authorization mechanism on the client side until a patch is available, and ensure that all authorization requests are validated on the server side to prevent privilege escalation. Additionally, restrict access to admin-level functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-31525

Produtos afetados

Peppermint Ticket Management