Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin and gain complete access to the system as the authorization mechanism is not validated on the server side and only on the client side. This can result, for example, in creating a new admin user in the system which enables persistent access for the attacker as an administrator.
References
Configurations
No configuration.
History
06 Mar 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
CWE | CWE-306 | |
References | () https://github.com/Peppermint-Lab/peppermint/issues/258 - |
05 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-05 19:15
Updated : 2025-03-06 15:15
NVD link : CVE-2024-31525
Mitre link : CVE-2024-31525
CVE.ORG link : CVE-2024-31525
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function