/api/user/users in the web GUI for the Cubro EXA48200...
Moderate severity
Unreviewed
Published
Mar 3, 2025
to the GitHub Advisory Database
•
Updated Mar 5, 2025
Description
Published by the National Vulnerability Database
Mar 3, 2025
Published to the GitHub Advisory Database
Mar 3, 2025
Last updated
Mar 5, 2025
/api/user/users in the web GUI for the Cubro EXA48200 network packet broker (build 20231025055018) fixed in V5.0R14.5P4-V3.3R1 allows remote authenticated users of the application to increase their privileges by sending a single HTTP PUT request with rolename=Administrator, aka incorrect access control.
References