PT-2024-32479 · Unknown · Gladys Assistant

Chasebowman-Contrast

·

Published

2024-09-21

·

Updated

2024-09-26

·

CVE-2024-47210

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gladys Assistant versions prior to 4.45.1
Description The issue allows a user to change their own role, resulting in privilege escalation. This is possible because the req.body.role can be used in the updateMySelf function in server/api/controllers/user.controller.js.
Recommendations For versions prior to 4.45.1, update to version 4.45.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the updateMySelf function in server/api/controllers/user.controller.js to prevent exploitation. Additionally, avoid using the req.body.role variable in the affected API endpoint until the issue is resolved.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47210

Affected Products

Gladys Assistant