facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, when a user updates their profile, a POST request containing user information is sent to the endpoint server/fm-modules/facileManager/ajax/processPost.php. It was found that non-admins can arbitrarily set their permissions and grant their non-admin accounts with super user privileges.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-01-31T22:33:11.697Z
Updated: 2024-08-01T23:19:52.854Z
Reserved: 2024-01-25T15:09:40.211Z
Link: CVE-2024-24573
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2024-01-31T23:15:08.560
Modified: 2024-02-07T17:35:51.680
Link: CVE-2024-24573
Redhat
No data.