CVE-2025-4433

Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrative user with both "User Management" and "User Group Management" permissions to perform privilege escalation by adding users to groups with administrative privileges.
Configurations

No configuration.

History

30 May 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

30 May 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-30 13:15

Updated : 2025-05-30 16:31


NVD link : CVE-2025-4433

Mitre link : CVE-2025-4433

CVE.ORG link : CVE-2025-4433


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control