OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is required with OE_ADMIN role privilege.
This Cyber News was published on www.tenable.com. Publication date: Sat, 26 Oct 2024 03:26:02 +0000