CVE-2024-36691

Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify users' account information.
Configurations

No configuration.

History

21 Aug 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3
CWE CWE-277

13 Jun 2024, 18:36

Type Values Removed Values Added
Summary
  • (es) Los permisos inseguros en el método AdminController.AjaxSave() de PPGo_Jobs v2.8.0 permiten a atacantes autenticados modificar arbitrariamente la información de la cuenta de los usuarios.

12 Jun 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-12 15:15

Updated : 2024-08-21 17:35


NVD link : CVE-2024-36691

Mitre link : CVE-2024-36691

CVE.ORG link : CVE-2024-36691


JSON object : View

Products Affected

No product.

CWE
CWE-277

Insecure Inherited Permissions