Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-11-13 23:15
Updated : 2024-11-25 20:15
NVD link : CVE-2024-40408
Mitre link : CVE-2024-40408
CVE.ORG link : CVE-2024-40408
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function