Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
Metrics
Affected Vendors & Products
References
History
Mon, 25 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cybelesoft
Cybelesoft thinfinity Workspace |
|
Weaknesses | CWE-306 | |
CPEs | cpe:2.3:a:cybelesoft:thinfinity_workspace:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cybelesoft
Cybelesoft thinfinity Workspace |
|
Metrics |
cvssV3_1
|
Wed, 13 Nov 2024 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-13T00:00:00
Updated: 2024-11-25T19:49:16.131Z
Reserved: 2024-07-05T00:00:00
Link: CVE-2024-40408
Vulnrichment
Updated: 2024-11-25T19:38:33.426Z
NVD
Status : Awaiting Analysis
Published: 2024-11-13T23:15:04.060
Modified: 2024-11-25T20:15:07.617
Link: CVE-2024-40408
Redhat
No data.