PT-2023-11442 · Unknown · Searchblox

CVE-2020-10130

·

Publicado

2023-09-06

·

Atualizado

2023-09-11

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SearchBlox versions prior to 9.1
Description The issue allows a user to bypass business logic and create multiple super admin users in the system. This can be exploited by manipulating the system's user creation mechanism.
Recommendations For versions prior to 9.1, update to version 9.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the user creation functionality to prevent unauthorized creation of super admin users.

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-10130

Produtos afetados

Searchblox