PT-2024-30846 · Geek Code · Geek Code Lab Login As Users

Ananda Dhakal

·

Published

2024-11-01

·

Updated

2024-11-08

·

CVE-2024-43982

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Geek Code Lab Login As Users versions 1.4.3 and earlier
Description The issue is related to a Missing Authorization vulnerability, which allows exploiting incorrectly configured access control security levels. This can lead to unauthorized access due to incorrect security settings.
Recommendations For versions 1.4.3 and earlier, update to version 1.4.4 to resolve the issue. As a temporary workaround, consider restricting access to the Login As Users plugin until the update is applied.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-43982

Affected Products

Geek Code Lab Login As Users