PT-2022-12236 · Unknown · Single Connect

Gokhan Sahin

·

Published

2022-01-27

·

Updated

2026-05-18

·

CVE-2021-44795

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Single Connect (affected versions not specified)
Description The issue arises from the lack of an authorization check in Single Connect when utilizing the sc-assigned-credential-ui module. This allows a remote attacker to potentially modify user permissions without authentication, including the possibility of deleting permissions from other users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-44795

Affected Products

Single Connect