9.8
CVE-2024-55507
- EPSS 0.58%
- Veröffentlicht 03.01.2025 16:15:26
- Zuletzt bearbeitet 03.04.2025 14:04:17
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Codeastro ≫ Complaint Management System Version1.0 SwEdition-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.58% | 0.681 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-281 Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.