PT-2024-15491 · Unknown · Mandelo Ssm Shiro Blog

Heishou

·

Published

2024-01-09

·

Updated

2024-05-17

·

CVE-2024-0356

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mandelo ssm shiro blog version 1.0
Description A vulnerability has been found in the file updateRoles of the component Backend, leading to improper access controls. The manipulation of this vulnerability can be used to exploit the issue.
Recommendations For Mandelo ssm shiro blog version 1.0, consider restricting access to the updateRoles functionality in the Backend component until a patch is available. As a temporary workaround, disabling the updateRoles function may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-0356

Affected Products

Mandelo Ssm Shiro Blog