PT-2026-95935 · Aiyiyi121 · Sxdevops
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X |
Name of the Vulnerable Software and Affected Versions
aiyiyi121 SxDevOps versions 1.0 through 1.1
Description
An issue exists in the
UserSerializer component within the backend/rbac/serializers.py file. A remote attacker can manipulate the update() function to cause improper privilege management.Recommendations
Apply patch 2b4bf8585c3e731e7a8af30801ea46680bc783f9 for versions 1.0 through 1.1.
As a temporary mitigation, restrict access to the
update() function in the UserSerializer component.Exploit
Fix
Incorrect Privilege Assignment
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sxdevops