CVE-2024-23831
CVSS V2 None
CVSS V3 None
Description
LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin into clicking on a link which automatically submits a request to setup.pl without the admin's consent. This request can be used to create a new user account with full application (/login.pl) privileges, leading to privilege escalation. The vulnerability is patched in versions 1.10.30 and 1.11.9.
Overview
- CVE ID
- CVE-2024-23831
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-02-02T15:34:12.121Z
- Last Modified Date
- 2024-02-02T15:34:12.121Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/ledgersmb/LedgerSMB/security/advisories/GHSA-98ff-f638-qxjm | x_refsource_CONFIRM |
https://github.com/ledgersmb/LedgerSMB/commit/8c2ae5be68a782d62cb9c0e17c0127bf30ef4165 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-23831 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23831 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 07:05:15 | Added to TrackCVE |