VulnerAlert



PRODUCTS
30-05-2025 21:54

CVE-2024-7096 Vulnerabilidad documentada

4.2 MEDIUM
Tags
#exploit
#product
#config
#admin
#products
#vulnerability
#bypass
#privilege escalation
#privilege
#pass
#malicious
#flaw
#configuration
#allow
#attack
#access
Descripción
A privilege escalation vulnerability exists in multiple [Vendor Name] products due to a business logic flaw SOAP admin services. A malicious actor can create new user with elevated permissions only when all of the following conditions are met: * services accessible attacker. The deployment includes an internally used attribute that is not part default WSO2 product configuration. At least one custom role non-default permissions. attacker has knowledge and internal deployment. Exploiting this allows actors assign higher privileges self-registered users, bypassing intended access control mechanisms.
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3573/
Referencia
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2024-7096
Resultados similares
Coincidentes en almenos en 50% de los tags
02-06-2025 CVE-2024-7074
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validat...
Ver información
02-06-2025 CVE-2024-3509
A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple ...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por