CVE-2022-38351

A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:supremainc:biostar_2:2.8.16:*:*:*:*:*:*:*

History

21 Nov 2024, 07:16

Type Values Removed Values Added
References () https://nobugescapes.com/blog/privilege-escalation-from-user-operator-to-system-administrator/ - Exploit, Third Party Advisory () https://nobugescapes.com/blog/privilege-escalation-from-user-operator-to-system-administrator/ - Exploit, Third Party Advisory
References () https://nobugescapes.com/wp-content/uploads/2022/08/Part1.docx - Exploit, Third Party Advisory () https://nobugescapes.com/wp-content/uploads/2022/08/Part1.docx - Exploit, Third Party Advisory

Information

Published : 2022-09-19 21:15

Updated : 2024-11-21 07:16


NVD link : CVE-2022-38351

Mitre link : CVE-2022-38351

CVE.ORG link : CVE-2022-38351


JSON object : View

Products Affected

supremainc

  • biostar_2
CWE
CWE-269

Improper Privilege Management