ZeroHour

CVE-2023-38989

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p34
Published
()
Modified
Description

An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete the Administrator's role information.

Vendors
jeesite
Products
jeesite
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.