Gin-vue-admin is a backstage management system based on vue and gin. In versions prior to 2.4.7 low privilege users are able to modify higher privilege users. Authentication is missing on the `setUserInfo` function. Users are advised to update as soon as possible. There are no known workarounds.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-02-09T19:55:09
Updated: 2024-08-03T02:46:39.546Z
Reserved: 2021-11-16T00:00:00
Link: CVE-2022-21660
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-02-09T20:15:12.550
Modified: 2024-11-21T06:45:10.633
Link: CVE-2022-21660
Redhat
No data.