Incorrect user role checking in multiple REST API...
High severity
Unreviewed
Published
Dec 12, 2023
to the GitHub Advisory Database
•
Updated Dec 22, 2023
Description
Published by the National Vulnerability Database
Dec 12, 2023
Published to the GitHub Advisory Database
Dec 12, 2023
Last updated
Dec 22, 2023
Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve privilege escalation via REST API endpoint invocation.
References