CVE-2024-47210 Information
Sep 22, 2024
cve
Description
Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.
Reference
https://github.com/GladysAssistant/Gladys/compare/v4.45.0…v4.45.1 https://github.com/GladysAssistant/Gladys/pull/2115 https://github.com/GladysAssistant/Gladys/commit/344ad9b8ca3078d9292dd95f2dd7b9172bc6ebbe
Share on: