PT-2022-11988 · Konga · Konga

Published

2022-03-28

·

Updated

2022-07-12

·

CVE-2021-44103

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions KONGA version 0.14.9
Description The issue allows attackers to escalate privileges from higher privilege users to full administration access. This is achieved through a crafted condition, as demonstrated by the "/api/user/{ID}" endpoint at the ADMIN parameter.
Recommendations For KONGA version 0.14.9, consider disabling access to the "/api/user/{ID}" endpoint until a patch is available. Restrict the use of the ADMIN parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-44103

Affected Products

Konga