Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve privilege escalation via REST API endpoint invocation.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.cvcn.gov.it/cvcn/cve/CVE-2023-36646 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-12-11T00:00:00
Updated: 2024-08-02T16:52:54.018Z
Reserved: 2023-06-25T00:00:00
Link: CVE-2023-36646
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-12T00:15:28.757
Modified: 2024-11-21T08:10:10.720
Link: CVE-2023-36646
Redhat
No data.