CVE-2022-2023
20.06.2022, 04:15
Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.Enginsight
Vendor | Product | Version |
---|---|---|
trudesk_project | trudesk | 𝑥 < 1.2.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-648 - Incorrect Use of Privileged APIsThe application does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
References