PT-2024-28833 · Cybele · Thinfinity Workspace
Published
2024-11-13
·
Updated
2024-11-25
·
CVE-2024-40408
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Cybele Software Thinfinity Workspace versions prior to 7.0.2.113
Description
The issue is related to an access control problem in the Create Profile section, allowing attackers to create arbitrary user profiles with elevated privileges. This can lead to unauthorized access.
Recommendations
For versions prior to 7.0.2.113, update to version 7.0.2.113 or later to resolve the issue. As a temporary workaround, consider restricting access to the Create Profile section until the update is applied.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thinfinity Workspace