Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles to obtain email addresses via the "Get users" feature. The vulnerability occurs due to a flaw in permission verification logic, where the wildcard character in permitted URLs grants unintended access to endpoints restricted to users with Super Admin roles. This makes it possible for attackers to disclose the email addresses of all users.
References
Configurations
No configuration.
History
04 Dec 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CWE | CWE-863 |
25 Nov 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-25 21:15
Updated : 2024-12-04 17:15
NVD link : CVE-2024-50671
Mitre link : CVE-2024-50671
CVE.ORG link : CVE-2024-50671
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization