PT-2024-5482 · Microsoft · Groupme

Jonah Hook

·

Published

2024-06-12

·

Updated

2024-09-05

·

CVE-2024-38164

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GroupMe (affected versions not specified)
Description The issue is related to improper access control in the GroupMe mobile application, allowing an unauthenticated attacker to elevate privileges over a network. This can be achieved by convincing a user to click on a malicious link. There is no information provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-06131
CVE-2024-38164

Affected Products

Groupme