PT-2021-20023 · Labcup · Labcup

Alberto Chica Nunez

·

Published

2021-06-10

·

Updated

2021-06-22

·

CVE-2021-33031

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions LabCup versions prior to 6.3.0.03
Description The issue allows unauthorized actions to be performed by users without access to user management, potentially leading to account takeover. An attacker can change another user's email address if they know specific details about the victim, such as roles, group roles, ID, and remote authentication ID settings, which are sent in a modified save API request to the "save API" endpoint.
Recommendations For versions prior to 6.3.0.03, update to version 6.3.0.03 to resolve the issue. As a temporary workaround, consider restricting access to the save API endpoint until the update is applied.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33031

Affected Products

Labcup