ZeroHour

CVE-2019-11218

CVSS 3.0
8.8 high
EPSS
1%p65
Published
()
Modified
Description

Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenticated users to gain application administrator privileges via additional form parameter submissions.

Vendors
bonobogitserver
Products
bonobo git server
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.