A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin?do=admin:user:editPost of the component User Management Page. The manipulation leads to improper handling of insufficient privileges. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
History

Thu, 19 Dec 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Classcms
Classcms classcms
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:classcms:classcms:*:*:*:*:*:*:*:*
Vendors & Products Classcms
Classcms classcms

Tue, 17 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin?do=admin:user:editPost of the component User Management Page. The manipulation leads to improper handling of insufficient privileges. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Title ClassCMS User Management Page admin insufficient privileges
Weaknesses CWE-266
CWE-274
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-12-16T20:00:12.804Z

Updated: 2024-12-17T14:29:37.195Z

Reserved: 2024-12-16T08:53:03.678Z

Link: CVE-2024-12666

cve-icon Vulnrichment

Updated: 2024-12-17T14:29:32.191Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-16T20:15:09.430

Modified: 2024-12-19T15:01:00.497

Link: CVE-2024-12666

cve-icon Redhat

No data.