CVE-2024-40531

A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions.
Configurations

No configuration.

History

14 Mar 2025, 18:15

Type Values Removed Values Added
CWE CWE-284

24 Oct 2024, 20:35

Type Values Removed Values Added
CWE CWE-284

28 Aug 2024, 19:15

Type Values Removed Values Added
Summary (en) An issue in UAB Lexita PanteraCRM CMS v.401.152 and Patera CRM CMS v.402.072 allows a remote attacker to escalate privileges via the user profile management function. (en) A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions.

07 Aug 2024, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-284

06 Aug 2024, 16:30

Type Values Removed Values Added
Summary
  • (es) Un problema en UAB Lexita PanteraCRM CMS v.401.152 y Patera CRM CMS v.402.072 permite a un atacante remoto escalar privilegios a través de la función de gestión de perfiles de usuario.

05 Aug 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-05 16:15

Updated : 2025-03-14 18:15


NVD link : CVE-2024-40531

Mitre link : CVE-2024-40531

CVE.ORG link : CVE-2024-40531


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control