PT-2025-50231 · Openbmc · Useradmin+1

Published

2025-12-09

·

Updated

2025-12-17

·

CVE-2021-47701

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenBMCS version 2.4
Description The software contains a flaw that allows privilege escalation from a read user to an admin user. This is achieved by manipulating permissions and exploiting a weakness in the update user permissions.php script. An attacker can submit a malicious HTTP POST request to PHP scripts located in the '/plugins/useradmin/' directory to carry out this attack.
Recommendations Apply updates to address the issue in the update user permissions.php script. Restrict access to PHP scripts within the '/plugins/useradmin/' directory.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-47701

Affected Products

Openbmc
Useradmin