8.8
CVSSv3

CVE-2023-36646

Published: 12/12/2023 Updated: 13/12/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve privilege escalation via REST API endpoint invocation.

Vulnerable Product Search on Vulmon Subscribe to Product

prolion cryptospike 3.0.15