PT-2022-14166 · Erudika · Erudika/Para
Published
2022-05-24
·
Updated
2022-06-03
·
CVE-2022-1848
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
erudika/para versions prior to 1.45.11
Paraara versions prior to 1.46.0
Description
The issue concerns business logic errors in the GitHub repository erudika/para and Paraara. A user can create more than one app, even after they reach the app limit.
Recommendations
For erudika/para versions prior to 1.45.11, update to version 1.45.11 or later to resolve the issue.
For Paraara versions prior to 1.46.0, update to version 1.46.0 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Erudika/Para