Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v9j-x5gc-mg8x

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.

admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.

EPSS

Процентиль: 92%
0.08342
Низкий

Связанные уязвимости

nvd
больше 13 лет назад

admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.

EPSS

Процентиль: 92%
0.08342
Низкий