PT-2024-21296 · Opencti · Opencti
Walterone
·
Published
2024-05-23
·
Updated
2024-12-28
·
CVE-2024-26139
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
OpenCTI (affected versions not specified)
Description
The issue is related to a lack of certain security controls on the profile edit functionality in OpenCTI, allowing an authenticated attacker with low privileges to gain administrative privileges on the web application.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opencti