CVE-2020-36969
EUVD-2020-3088128.01.2026, 18:16
M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tildeslash | m\/monit | 3.7.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases