CVE-2024-4843

ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the client task and client task assignments, hence escalating his/her privilege.
Configurations

No configuration.

History

16 May 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-16 06:15

Updated : 2024-05-16 13:03


NVD link : CVE-2024-4843

Mitre link : CVE-2024-4843

CVE.ORG link : CVE-2024-4843


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key