PT-2024-13020 · Unknown · Profilepress

Revan Arifio

·

Published

2024-05-17

·

Updated

2024-05-17

·

CVE-2023-41954

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions ProfilePress versions through 4.13.1
Description The issue is related to Improper Privilege Management, allowing Privilege Escalation in ProfilePress Membership Team ProfilePress.
Recommendations For versions through 4.13.1, update to a version later than 4.13.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive features that may be exploited due to the Improper Privilege Management vulnerability until a patch is available.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2023-41954

Affected Products

Profilepress