CVE-2024-40531

A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions.
Configurations

No configuration.

History

14 Mar 2025, 18:15

Type Values Removed Values Added
CWE CWE-284

Information

Published : 2024-08-05 16:15

Updated : 2025-03-14 18:15


NVD link : CVE-2024-40531

Mitre link : CVE-2024-40531

CVE.ORG link : CVE-2024-40531


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control