A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Applications using Mendix 10 (V10.6) (All versions < V10.6.9), Mendix Applications using Mendix 9 (All versions >= V9.3.0 < V9.24.22). Affected applications could allow users with the capability to manage a role to elevate the access rights of users with that role. Successful exploitation requires to guess the id of a target role which contains the elevated access rights.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2024-06-11T11:15:43.422Z
Updated: 2024-09-06T17:00:43.293Z
Reserved: 2024-04-23T12:07:54.905Z
Link: CVE-2024-33500
Vulnrichment
Updated: 2024-08-02T02:36:03.343Z
NVD
Status : Awaiting Analysis
Published: 2024-06-11T12:15:15.957
Modified: 2024-11-21T09:17:02.433
Link: CVE-2024-33500
Redhat
No data.