PT-2024-27739 · 14Finger · 14Finger
K3Ppf0R
·
Published
2024-07-05
·
Updated
2024-07-08
·
CVE-2024-37768
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
14Finger version 1.1
Description
The issue allows for arbitrary user deletion through the "/api/admin/user?id" API endpoint. This endpoint is used for administrative purposes, and the vulnerability could be exploited to delete users without proper authorization.
Recommendations
For version 1.1, consider disabling access to the "/api/admin/user?id" API endpoint until a patch is available to prevent exploitation. Restricting the use of the
id parameter in this endpoint can also help minimize the risk.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
14Finger