Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jh7-8c9c-w8mx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.

Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.

EPSS

Процентиль: 41%
0.00189
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 4.9
nvd
почти 5 лет назад

Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.

EPSS

Процентиль: 41%
0.00189
Низкий

Дефекты

CWE-269