Zafiyet İstihbaratı

CVE-2024-57726 — SimpleHelp Missing Authorization Vulnerability

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

CVECVE-2024-57726CVSSEPSSExploitCISA KEVVendorSimpleHelpÜrünSimpleHelp

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

CISA tarafından önerilen aksiyon

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Bu içerik yararlı oldu mu?Geri bildirim bu cihazda saklanır; varsayılan olarak sunucuya gönderilmez.