Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
References
Link | Resource |
---|---|
https://blog.cybelesoft.com/thinfinity-workspace-security-bulletin-nov-2024/ | Vendor Advisory |
Configurations
History
01 May 2025, 14:24
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:cybelesoft:thinfinity_workspace:*:*:*:*:*:*:*:* | |
References | () https://blog.cybelesoft.com/thinfinity-workspace-security-bulletin-nov-2024/ - Vendor Advisory | |
First Time |
Cybelesoft
Cybelesoft thinfinity Workspace |
25 Nov 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.3 |
CWE | CWE-306 |
15 Nov 2024, 13:58
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
13 Nov 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-13 23:15
Updated : 2025-05-01 14:24
NVD link : CVE-2024-40408
Mitre link : CVE-2024-40408
CVE.ORG link : CVE-2024-40408
JSON object : View
Products Affected
cybelesoft
- thinfinity_workspace
CWE
CWE-306
Missing Authentication for Critical Function