PT-2024-15827 · Softwarex · Softwarex
Published
2024-03-02
·
Updated
2025-01-21
·
CVE-2024-0795
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
The affected software is related to a specific application or system that uses admin or manager roles. If an attacker gains access to an instance with the admin or manager role, they can create a new user with an admin role without any backend authentication to prevent it, allowing them to use the new account to gain elevated privileges on the instance.
An exploit is available, which enables attackers to bypass backend authentication and escalate privileges.
More information about the issue can be found at https://t.co/MlDvjfDMxj and https://t.co/zwHifLKZSu.
#AdminRole #ElevatedPrivileges #BackendAuthentication #InstanceAccess #PrivilegeEscalation #SecurityRisk #ExploitAvailable #AuthenticationBypass
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Softwarex