PT-2024-15827 · Softwarex · Softwarex

Published

2024-03-02

·

Updated

2025-01-21

·

CVE-2024-0795

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The affected software is related to a specific application or system that uses admin or manager roles. If an attacker gains access to an instance with the admin or manager role, they can create a new user with an admin role without any backend authentication to prevent it, allowing them to use the new account to gain elevated privileges on the instance. An exploit is available, which enables attackers to bypass backend authentication and escalate privileges. More information about the issue can be found at https://t.co/MlDvjfDMxj and https://t.co/zwHifLKZSu. #AdminRole #ElevatedPrivileges #BackendAuthentication #InstanceAccess #PrivilegeEscalation #SecurityRisk #ExploitAvailable #AuthenticationBypass

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-0795

Affected Products

Softwarex