PT-2023-20952 · Unknown · Opengoofy Hippo4J

Laoquanshi

·

Published

2023-03-16

·

Updated

2025-02-26

·

CVE-2023-27095

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenGoofy Hippo4j version 1.4.3
Description The issue allows an attacker to escalate privileges via the AddUser method of the UserController function in the Tenant Management module. This is due to an Insecure Permissions vulnerability.
Recommendations For OpenGoofy Hippo4j version 1.4.3, consider disabling the AddUser method of the UserController function in the Tenant Management module as a temporary workaround until a patch is available. Restrict access to the Tenant Management module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-27095
GHSA-XG89-VVWP-9C27

Affected Products

Opengoofy Hippo4J