PT-2025-2646 · Unknown · Admin/Site Enhancements (Ase) Pro

Rafie Muhammad

·

Published

2025-02-03

·

Updated

2025-02-08

·

CVE-2024-43333

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Admin and Site Enhancements (ASE) Pro versions 7.6.2.1 and earlier
Description The issue is related to an Incorrect Privilege Assignment vulnerability, which allows Privilege Escalation. This means that users with lower privileges may be able to gain higher privileges, potentially leading to unauthorized access or control.
Recommendations For Admin and Site Enhancements (ASE) Pro versions 7.6.2.1 and earlier, consider restricting access to sensitive features or modules until a patch or fix is available. As a temporary workaround, review and adjust privilege assignments to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2024-43333

Affected Products

Admin/Site Enhancements (Ase) Pro