CVE-2024-9970
15.10.2024, 04:15
The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.Enginsight
Vendor | Product | Version |
---|---|---|
newtype | flowmaster_bpm_plus | 𝑥 < 5.3.1 |
𝑥
= Vulnerable software versions