A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Mar 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 |
Thu, 24 Oct 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 |
Wed, 28 Aug 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue in UAB Lexita PanteraCRM CMS v.401.152 and Patera CRM CMS v.402.072 allows a remote attacker to escalate privileges via the user profile management function. | A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions. |
Wed, 07 Aug 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Uab Lexita
Uab Lexita panteracrm Cms Uab Lexita patera Crm Cms |
|
Weaknesses | CWE-284 | |
CPEs | cpe:2.3:a:uab_lexita:panteracrm_cms:*:*:*:*:*:*:*:* cpe:2.3:a:uab_lexita:patera_crm_cms:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Uab Lexita
Uab Lexita panteracrm Cms Uab Lexita patera Crm Cms |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-14T18:11:11.708Z
Reserved: 2024-07-05T00:00:00.000Z
Link: CVE-2024-40531

Updated: 2024-08-07T18:43:16.060Z

Status : Awaiting Analysis
Published: 2024-08-05T16:15:36.800
Modified: 2025-03-14T18:15:28.753
Link: CVE-2024-40531

No data.