CVE-2023-37498
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. I
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It is possible that an attacker could potentially escalate their privileges.
HIGH · CVSS 8.1
EPSS 0.0037
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0