Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gladysassistant
Gladysassistant gladys Assistant |
|
Weaknesses | CWE-400 | |
CPEs | cpe:2.3:a:gladysassistant:gladys_assistant:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gladysassistant
Gladysassistant gladys Assistant |
|
Metrics |
cvssV3_1
|
Sat, 21 Sep 2024 22:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-23T15:26:54.395Z
Reserved: 2024-09-21T00:00:00
Link: CVE-2024-47210

Updated: 2024-09-23T15:26:47.395Z

Status : Awaiting Analysis
Published: 2024-09-21T23:15:14.137
Modified: 2024-09-26T13:32:55.343
Link: CVE-2024-47210

No data.