vendor:
SmartAgent
by:
Orion Hridoy
CVSS
LOW
Privilege Escalation
N/A
CWE
Product Name: SmartAgent
Affected Version From: 3.1.0
Affected Version To: 3.1.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10/Kali Linux
2021
SmartAgent 3.1.0 – Privilege Escalation
A Low grade user like ViewOnly can create an account with SuperUser permission. Steps To Reproduce: 1. Create a user with ViewOnly 2. Visit https://demo.localhost.com/#/CampaignManager/users 3. Now you will be able to create an account with SuperUser.
Mitigation:
Ensure that users are not able to create accounts with higher privileges than they are assigned.