ZeroHour

CVE-2022-38577

PoC ×2
CVSS 3.1
8.8 high
EPSS
2%p75
Published
()
Modified
Description

ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.

Vendors
processmaker
Products
processmaker
Weakness
CWE-281
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.