CVE-2022-2921
21.08.2022, 04:15
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An attacker can gain access to protected functionality such as create/update companies, install/update languages, install/activate extensions, install/activate themes and other permissive actions.Enginsight
Vendor | Product | Version |
---|---|---|
notrinos | notrinoserp | 𝑥 < 0.7 |
𝑥
= Vulnerable software versions
References