7.3
CVE-2024-40408
- EPSS 0.3%
- Veröffentlicht 13.11.2024 23:15:04
- Zuletzt bearbeitet 01.05.2025 14:24:20
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cybelesoft ≫ Thinfinity Workspace Version < 7.0.2.113
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.527 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.3 | 3.9 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.