CVE-2020-11679

CVE-2020-11679

Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionality. Adminstrator/Users/Edit/:UserId fails to check that the request was submitted by an Administrator. This allows a normal user to escalate their privileges by adding additional roles to their account.

Source: CVE-2020-11679

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다