Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrr8-7rwv-p26v

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The canUpdate function in model/MRole.java in Adempiere before 3.1.6 does not properly validate user roles, which allows remote authenticated read-only users to gain read-write privileges. NOTE: some of these details are obtained from third party information.

The canUpdate function in model/MRole.java in Adempiere before 3.1.6 does not properly validate user roles, which allows remote authenticated read-only users to gain read-write privileges. NOTE: some of these details are obtained from third party information.

EPSS

Процентиль: 68%
0.00566
Низкий

Связанные уязвимости

nvd
больше 18 лет назад

The canUpdate function in model/MRole.java in Adempiere before 3.1.6 does not properly validate user roles, which allows remote authenticated read-only users to gain read-write privileges. NOTE: some of these details are obtained from third party information.

EPSS

Процентиль: 68%
0.00566
Низкий