ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the client task and client task assignments, hence escalating his/her privilege.
References
Link | Resource |
---|---|
https://thrive.trellix.com/s/article/000013505 |
Configurations
No configuration.
History
No history.
Information
Published : 2024-05-16 06:15
Updated : 2024-05-16 13:03
NVD link : CVE-2024-4843
Mitre link : CVE-2024-4843
CVE.ORG link : CVE-2024-4843
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key