A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Oct 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 |
Wed, 28 Aug 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue in UAB Lexita PanteraCRM CMS v.401.152 and Patera CRM CMS v.402.072 allows a remote attacker to escalate privileges via the user profile management function. | A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions. |
Wed, 07 Aug 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Uab Lexita
Uab Lexita panteracrm Cms Uab Lexita patera Crm Cms |
|
Weaknesses | CWE-284 | |
CPEs | cpe:2.3:a:uab_lexita:panteracrm_cms:*:*:*:*:*:*:*:* cpe:2.3:a:uab_lexita:patera_crm_cms:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Uab Lexita
Uab Lexita panteracrm Cms Uab Lexita patera Crm Cms |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-08-05T00:00:00
Updated: 2024-10-24T19:57:55.151Z
Reserved: 2024-07-05T00:00:00
Link: CVE-2024-40531
Vulnrichment
Updated: 2024-08-07T18:43:16.060Z
NVD
Status : Awaiting Analysis
Published: 2024-08-05T16:15:36.800
Modified: 2024-10-24T20:35:06.753
Link: CVE-2024-40531
Redhat
No data.