PT-2024-30846 · Geek Code · Geek Code Lab Login As Users

·

CVE-2024-43982

·

Published

2024-11-01

·

Updated

2024-11-08

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Geek Code Lab Login As Users versions 1.4.3 and earlier
Description The issue is related to a Missing Authorization vulnerability, which allows exploiting incorrectly configured access control security levels. This can lead to unauthorized access due to incorrect security settings.
Recommendations For versions 1.4.3 and earlier, update to version 1.4.4 to resolve the issue. As a temporary workaround, consider restricting access to the Login As Users plugin until the update is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-43982

Affected Products

Geek Code Lab Login As Users