PT-2026-7727 · Cipplanner · Cipace

CVE-2024-50619

·

Publicado

2026-02-11

·

Atualizado

2026-02-18

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CIPPlanner CIPAce versions prior to 9.17
Description Issues in the My Account and User Management components allow for access escalation. A user with low privileges can gain access to other accounts by manipulating the client’s user ID to modify account information. Additionally, a low-privileged authenticated user can elevate system privileges by modifying information associated with a disabled user role in the client.
Recommendations Update to version 9.17 or later.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-50619

Produtos afetados

Cipace