Privilege Elevation Vulnerability in FlowMaster BPM Plus System
CVE-2024-9970

8.8HIGH

Key Information:

Vendor
Newtype
Vendor
CVE Published:
15 October 2024

Summary

The FlowMaster BPM Plus system from NewType contains a privilege escalation vulnerability that allows remote attackers with standard user permissions to gain elevated privileges to the administrator level. This is achieved through manipulation of a specific cookie, which poses a significant risk to the integrity of systems utilizing this product. Users of FlowMaster BPM Plus are advised to implement security measures to mitigate this vulnerability and ensure the protection of sensitive information and access rights.

Affected Version(s)

FlowMaster BPM Plus 0 < 5.3.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-9970 : Privilege Elevation Vulnerability in FlowMaster BPM Plus System | SecurityVulnerability.io