vendor:
KONGA
by:
Fabricio Salomao & Paulo Trindade
8.8
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: KONGA
Affected Version From: 0.14.9
Affected Version To: 0.14.9
Patch Exists: YES
Related CWE:
CPE: a:pantsel:konga
Platforms Tested: Linux - Ubuntu 20.04.3 LTS (focal)
2021
KONGA 0.14.9 – Privilege Escalation
A vulnerability in KONGA 0.14.9 allows an attacker to escalate privileges by changing a normal user to an admin user. This is done by sending a PUT request to the /api/user/<user_id> endpoint with the admin parameter set to true and the token parameter set to the token obtained from the login request. This vulnerability can be exploited by an authenticated attacker.
Mitigation:
Upgrade to the latest version of KONGA.