8.8
CVSSv3

CVE-2022-38577

Published: 19/09/2022 Updated: 15/11/2022
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

ProcessMaker before v3.5.4 exists to contain insecure permissions in the user profile page. This vulnerability allows malicious users to escalate normal users to Administrators.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

processmaker processmaker

Exploits

ProcessMaker versions prior to 354 were discovered to be susceptible to a remote privilege escalation vulnerability ...

Github Repositories

ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.

ProcessMaker - User Profile Privilege Escalation CVE-2022-38577 ProcessMaker before v354 was discovered to contain insecure permissions in the user profile page This vulnerability allows attackers to escalate normal users to Administrators * This exploit can be used with the Metasploit module (ProcessMaker Plugin Upload) - exploit/multi/http/processmaker_plugin_upload to ga

Hi there πŸ‘‹ πŸ”­ I’m currently working on: Information Security Engineer / Consultant / Penetration Tester 🌱 I’m currently learning: Cyber Security πŸŽ“ Education: King Mongkut's University of Technology North Bangkok Bachelor of Science in Technical Education (BSTechEd) Sukhothai Thammathirat Open University Sumrit Certificate 87 (Science and Te