PT-2025-14381 · Unknown · Hackathon-Starter

Published

2025-04-01

·

Updated

2025-04-05

·

CVE-2025-29036

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions hackathon-starter version 8.1.0
Description The issue allows a remote attacker to escalate privileges via the user.js component. This enables the attacker to gain higher access levels, potentially leading to further exploitation of the system.
Recommendations For hackathon-starter version 8.1.0, consider disabling the user.js component until a patch is available to prevent privilege escalation. Restrict access to sensitive areas of the system to minimize the risk of exploitation.

Exploit

Fix

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-29036

Affected Products

Hackathon-Starter