Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.
References
Configurations
No configuration.
History
23 Sep 2024, 16:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-400 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
Summary |
|
21 Sep 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-21 23:15
Updated : 2024-09-26 13:32
NVD link : CVE-2024-47210
Mitre link : CVE-2024-47210
CVE.ORG link : CVE-2024-47210
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption