CVE-2024-50619

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's accounts by tampering with the client's user id to change their account information. A low-privileged authenticated user can elevate his or her system privileges by modifying the information of a user role that is disabled in the client.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cipplanner:cipace:*:*:*:*:*:*:*:*

History

17 Jun 2026, 08:04

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidades en los componentes Mi Cuenta y Gestión de Usuarios en CIPPlanner CIPAce anterior a la versión 9.17 permiten a los atacantes escalar sus niveles de acceso. Un usuario autenticado de bajo privilegio puede obtener acceso a las cuentas de otras personas manipulando el ID de usuario del cliente para cambiar la información de su cuenta. Un usuario autenticado de bajo privilegio puede elevar sus privilegios de sistema modificando la información de un rol de usuario que está deshabilitado en el cliente.

13 Feb 2026, 21:39

Type Values Removed Values Added
CPE cpe:2.3:a:cipplanner:cipace:*:*:*:*:*:*:*:*
References () https://cipplanner.com/cve-2024-50619-cve-public-notification-of-resolution/ - () https://cipplanner.com/cve-2024-50619-cve-public-notification-of-resolution/ - Vendor Advisory
First Time Cipplanner cipace
Cipplanner

12 Feb 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-269

11 Feb 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 22:15

Updated : 2026-06-17 08:04


NVD link : CVE-2024-50619

Mitre link : CVE-2024-50619

CVE.ORG link : CVE-2024-50619


JSON object : View

Products Affected

cipplanner

  • cipace
CWE
CWE-269

Improper Privilege Management