If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have elevated privileges on the instance
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-03-02 22:15
Updated : 2024-03-04 13:58
NVD link : CVE-2024-0795
Mitre link : CVE-2024-0795
CVE.ORG link : CVE-2024-0795
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control