Authorization Bypass Through User-Controlled Key Vulnerability
CVE-2024-43916
4.3MEDIUM
What is CVE-2024-43916?
An authorization bypass vulnerability exists in the Zephyr Project Manager developed by Dylan James, which allows attackers to exploit user-controlled keys to access unauthorized functionalities. This issue affects versions of the software up to 3.3.102. By leveraging this vulnerability, malicious actors could bypass normal access controls, potentially leading to unauthorized actions within the application. Users of the affected versions are advised to apply security patches and mitigate risks associated with this flaw.
Affected Version(s)
Zephyr Project Manager <= 3.3.102