CVE-2024-37758

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Dec 20, 2024
CWE ID 352

Summary

CVE-2024-37758 is a vulnerability affecting Digiteam v4.21.0.0. This issue involves improper access control in the endpoint /RoleMenuMapping/AddRoleMenu, enabling authenticated attackers to escalate their privileges beyond intended limits. Successful exploitation could result in unauthorized access to sensitive information or system functionality. Organizations using this version of Digiteam are advised to apply the forthcoming patch to mitigate this risk. Until then, access to this endpoint should be restricted to authorized personnel only.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share