A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page.
References
Link | Resource |
---|---|
https://nobugescapes.com/blog/privilege-escalation-from-user-operator-to-system-administrator/ | Exploit Third Party Advisory |
https://nobugescapes.com/wp-content/uploads/2022/08/Part1.docx | Exploit Third Party Advisory |
https://nobugescapes.com/blog/privilege-escalation-from-user-operator-to-system-administrator/ | Exploit Third Party Advisory |
https://nobugescapes.com/wp-content/uploads/2022/08/Part1.docx | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 07:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://nobugescapes.com/blog/privilege-escalation-from-user-operator-to-system-administrator/ - Exploit, Third Party Advisory | |
References | () https://nobugescapes.com/wp-content/uploads/2022/08/Part1.docx - Exploit, Third Party Advisory |
Information
Published : 2022-09-19 21:15
Updated : 2024-11-21 07:16
NVD link : CVE-2022-38351
Mitre link : CVE-2022-38351
CVE.ORG link : CVE-2022-38351
JSON object : View
Products Affected
supremainc
- biostar_2
CWE
CWE-269
Improper Privilege Management