Description
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It is possible that an attacker could potentially escalate their privileges.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41385 | A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It is possible that an attacker could potentially escalate their privileges. |
References
History
Thu, 17 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2024-10-17T15:43:19.004Z
Reserved: 2023-07-06T16:11:32.538Z
Link: CVE-2023-37498
Updated: 2024-08-02T17:16:29.966Z
Status : Modified
Published: 2023-08-03T22:15:12.343
Modified: 2024-11-21T08:11:50.180
Link: CVE-2023-37498
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD