vendor:
Adive Framework
by:
Pablo Santiago
8.8
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Adive Framework
Affected Version From: 2.0.7
Affected Version To: 2.0.7
Patch Exists: YES
Related CWE: CVE-2019-14347
CPE: a:adive:adive_framework
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2019
Adive Framework 2.0.7 – Privilege Escalation
An attacker can exploit a vulnerability in Adive Framework 2.0.7 to gain elevated privileges. By sending a crafted request to the application, an attacker can create a new user with administrator privileges. This vulnerability is due to the lack of proper input validation and authentication checks. This allows an attacker to bypass authentication and gain elevated privileges.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of Adive Framework.