Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-09-21 23:15
Updated : 2024-09-26 13:32
NVD link : CVE-2024-47210
Mitre link : CVE-2024-47210
CVE.ORG link : CVE-2024-47210
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption