CVE-2024-33500

CVSS V2 None CVSS V3 None
Description
A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Applications using Mendix 10 (V10.6) (All versions < V10.6.9), Mendix Applications using Mendix 9 (All versions >= V9.3.0 < V9.24.22). Affected applications could allow users with the capability to manage a role to elevate the access rights of users with that role. Successful exploitation requires to guess the id of a target role which contains the elevated access rights.
Overview
  • CVE ID
  • CVE-2024-33500
  • Assigner
  • siemens
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-06-11T11:15:43.422Z
  • Last Modified Date
  • 2024-06-11T14:20:45.931Z
History
Created Old Value New Value Data Type Notes
2024-06-26 05:15:58 Added to TrackCVE