CVE-2024-40408

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cybelesoft:thinfinity_workspace:*:*:*:*:*:*:*:*

History

01 May 2025, 14:24

Type Values Removed Values Added
CPE cpe:2.3:a:cybelesoft:thinfinity_workspace:*:*:*:*:*:*:*:*
References () https://blog.cybelesoft.com/thinfinity-workspace-security-bulletin-nov-2024/ - () https://blog.cybelesoft.com/thinfinity-workspace-security-bulletin-nov-2024/ - Vendor Advisory
First Time Cybelesoft
Cybelesoft thinfinity Workspace

25 Nov 2024, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3
CWE CWE-306

15 Nov 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) Se descubrió que la versión anterior a v7.0.2.113 de Cybele Software Thinfinity Workspace contenía un problema de control de acceso en la sección Crear perfil. Esta vulnerabilidad permite a los atacantes crear perfiles de usuario arbitrarios con privilegios elevados.

13 Nov 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-13 23:15

Updated : 2025-05-01 14:24


NVD link : CVE-2024-40408

Mitre link : CVE-2024-40408

CVE.ORG link : CVE-2024-40408


JSON object : View

Products Affected

cybelesoft

  • thinfinity_workspace
CWE
CWE-306

Missing Authentication for Critical Function