Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f2mp-8fgg-7465

Опубликовано: 29 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Vertical Privilege Escalation in KONGA 0.14.9 allows attackers to higher privilege users to full administration access. The attack vector is a crafted condition, as demonstrated by the /api/user/{ID} at ADMIN parameter.

Vertical Privilege Escalation in KONGA 0.14.9 allows attackers to higher privilege users to full administration access. The attack vector is a crafted condition, as demonstrated by the /api/user/{ID} at ADMIN parameter.

8.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

nvd
почти 4 года назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42192. Reason: This candidate is a duplicate of CVE-2021-42192. Notes: All CVE users should reference CVE-2021-42192 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

8.8 High

CVSS3

Дефекты

CWE-269