CVE-2024-40408

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
Configurations

No configuration.

History

No history.

Information

Published : 2024-11-13 23:15

Updated : 2024-11-25 20:15


NVD link : CVE-2024-40408

Mitre link : CVE-2024-40408

CVE.ORG link : CVE-2024-40408


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function