Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mass assignment vulnerabilities and exploits
(subscribe to this query)
6
CVSSv2
CVE-2013-2113
The create method in app/controllers/users_controller.rb in Foreman prior to 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.
Redhat Openstack 3.0
Theforeman Foreman
Theforeman Foreman 1.1
1 EDB exploit
7.5
CVSSv3
CVE-2020-24940
An issue exists in Laravel prior to 6.18.34 and 7.x prior to 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a mass assignment.
Laravel Laravel
8.8
CVSSv3
CVE-2024-40531
A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions.
8.8
CVSSv3
CVE-2024-7297
Langflow versions before 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged malicious user to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.
5
CVSSv2
CVE-2008-7309
Insoshi prior to 20080920 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote malicious users to set the ForumPost user_id value via a modified URL, related to a "mass assignment" vulnerability.
Insoshi Insoshi
4
CVSSv2
CVE-2013-2506
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x prior to 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.
Spreecommerce Spree 1.1.0
Spreecommerce Spree 1.1.1
Spreecommerce Spree 1.1.2
Spreecommerce Spree 1.1.3
Spreecommerce Spree 1.1.4
Spreecommerce Spree 1.1.5
Spreecommerce Spree 1.1.6
Spreecommerce Spree 1.2.0
Spreecommerce Spree 1.2.1
Spreecommerce Spree 1.2.2
Spreecommerce Spree 1.2.3
Spreecommerce Spree 1.2.4
5
CVSSv2
CVE-2008-7310
Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote malicious users to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerabili...
Spreecommerce Spree 0.2.0
7.5
CVSSv3
CVE-2012-2055
GitHub Enterprise prior to 20120304 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote malicious users to set the public_key[user_id] value via a modified URL for the public-key update form, related to a "mass as...
Github Github
9.1
CVSSv3
CVE-2021-27582
org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect up to and including 1.3.3 contains a Mass Assignment (aka Autobinding) vulnerability. This arises due to unsafe usage of the @ModelAttribute annotation during the...
Mitreid Connect
6.5
CVSSv3
CVE-2018-20301
An issue exists in Steve Pallen Coherence prior to 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically...
Coherence Project Coherence
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
type confusion
unspecified
CVE-2025-24200
reflected XSS
panel
CVE-2024-12549
temporal technologies, inc.
CVE-2024-21971
CVE-2024-57777
CVE-2023-31122
CVE-2025-0909
winzip computing
unified secops platform
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »