CVE-2024-40408

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cybelesoft:thinfinity_workspace:*:*:*:*:*:*:*:*

History

01 May 2025, 14:24

Type Values Removed Values Added
First Time Cybelesoft thinfinity Workspace
Cybelesoft
CPE cpe:2.3:a:cybelesoft:thinfinity_workspace:*:*:*:*:*:*:*:*
References () https://blog.cybelesoft.com/thinfinity-workspace-security-bulletin-nov-2024/ - () https://blog.cybelesoft.com/thinfinity-workspace-security-bulletin-nov-2024/ - Vendor Advisory

Information

Published : 2024-11-13 23:15

Updated : 2025-05-01 14:24


NVD link : CVE-2024-40408

Mitre link : CVE-2024-40408

CVE.ORG link : CVE-2024-40408


JSON object : View

Products Affected

cybelesoft

  • thinfinity_workspace
CWE
CWE-306

Missing Authentication for Critical Function