Privilege Elevation Vulnerability in FlowMaster BPM Plus System
CVE-2024-9970
8.8HIGH
Summary
The FlowMaster BPM Plus system from NewType contains a privilege escalation vulnerability that allows remote attackers with standard user permissions to gain elevated privileges to the administrator level. This is achieved through manipulation of a specific cookie, which poses a significant risk to the integrity of systems utilizing this product. Users of FlowMaster BPM Plus are advised to implement security measures to mitigate this vulnerability and ensure the protection of sensitive information and access rights.
Affected Version(s)
FlowMaster BPM Plus 0 < 5.3.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved