Vulnerability CVE-2022-2921


Published: 2022-08-21

Description:
This will lead to privilege escalation from AP officers account to the System Administrator account. and gain more functionality such as Create/Update Companies. Install/Update Languages. Install/Activate Extensions. Install/Activate Themes. Install/Activate Chart of Accounts. Software Upgrade.

Type:

CWE-359

(Privacy Violation)

 References:
https://github.com/notrinos/notrinoserp/commit/1b9903f4deea3289872793e60d730c63ecbf7b45
https://huntr.dev/bounties/51b32a1c-946b-4390-a212-b6c4b6e4115c

Copyright 2024, cxsecurity.com

 

Back to Top