Incorrect Access Control in Sage DPW by Sage Group
CVE-2024-56883
8.1HIGH
What is CVE-2024-56883?
Sage DPW prior to version 2024_12_001 exhibits a flaw in its implementation of role-based access controls, enabling low-privileged users possessing employee role privileges to erroneously create external courses for other employees. This occurs because the server-side enforcement of access controls is inconsistent, allowing a user to alter a legitimate request's parameters, particularly by substituting their user ID with that of another employee. Such a vulnerability can lead to unauthorized access and potential misuse of the platform’s functionalities, compromising user privacy and data security.
