Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-50619

Опубликовано: 11 фев. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's accounts by tampering with the client's user id to change their account information. A low-privileged authenticated user can elevate his or her system privileges by modifying the information of a user role that is disabled in the client.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cipplanner:cipace:*:*:*:*:*:*:*:*
Версия до 9.17 (исключая)

EPSS

Процентиль: 14%
0.00232
Низкий

8.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 8.8
github
4 месяца назад

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's accounts by tampering with the client's user id to change their account information. A low-privileged authenticated user can elevate his or her system privileges by modifying the information of a user role that is disabled in the client.

EPSS

Процентиль: 14%
0.00232
Низкий

8.8 High

CVSS3

Дефекты

CWE-269