Improper Permission Configuration in 74cmsSE by 74cms
CVE-2022-41471

6.5MEDIUM

Key Information:

Vendor

74cms

Status
Vendor
CVE Published:
17 October 2022

What is CVE-2022-41471?

74cmsSE v3.12.0 contains a vulnerability that allows authenticated attackers with limited access rights to manipulate and alter the privileges associated with the Super Administrator account. This misconfiguration presents an elevated risk as it compromises the integrity of user roles and access controls, allowing unauthorized changes to critical administration credentials. Organizations using this version should take immediate action to review and secure their permission settings to mitigate potential exploits.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-41471 : Improper Permission Configuration in 74cmsSE by 74cms