An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/java/cn/niter/forum/controller/AdminController.java, allows attackers to gain escalated privileges.
References
Link | Resource |
---|---|
https://github.com/yourkevin/NiterForum/issues/25 | Exploit Issue Tracking Vendor Advisory |
https://github.com/yourkevin/NiterForum/issues/25 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
19 Mar 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 |
21 Nov 2024, 07:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/yourkevin/NiterForum/issues/25 - Exploit, Issue Tracking, Vendor Advisory |
23 Feb 2023, 05:03
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-02-15 22:15
Updated : 2025-03-19 18:15
NVD link : CVE-2022-38935
Mitre link : CVE-2022-38935
CVE.ORG link : CVE-2022-38935
JSON object : View
Products Affected
niter
- niterforum
CWE