SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Jan 2025 23:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2025-01-15T00:00:00
Updated: 2025-01-15T22:45:19.312287
Reserved: 2025-01-09T00:00:00
Link: CVE-2024-57726
Vulnrichment
No data.
NVD
Status : Received
Published: 2025-01-15T23:15:09.520
Modified: 2025-01-15T23:15:09.520
Link: CVE-2024-57726
Redhat
No data.