PT-2026-7727 · Cipplanner · Cipace
Published
2026-02-11
·
Updated
2026-02-18
·
CVE-2024-50619
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CIPPlanner CIPAce versions prior to 9.17
Description
Issues in the My Account and User Management components allow for access escalation. A user with low privileges can gain access to other accounts by manipulating the client’s user ID to modify account information. Additionally, a low-privileged authenticated user can elevate system privileges by modifying information associated with a disabled user role in the client.
Recommendations
Update to version 9.17 or later.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cipace