PT-2025-14381 · Unknown · Hackathon-Starter

CVE-2025-29036

·

Publicado

2025-04-01

·

Atualizado

2025-04-05

CVSS v3.1

5.9

Média

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions hackathon-starter version 8.1.0
Description The issue allows a remote attacker to escalate privileges via the user.js component. This enables the attacker to gain higher access levels, potentially leading to further exploitation of the system.
Recommendations For hackathon-starter version 8.1.0, consider disabling the user.js component until a patch is available to prevent privilege escalation. Restrict access to sensitive areas of the system to minimize the risk of exploitation.

Exploit

Correção

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-29036

Produtos afetados

Hackathon-Starter