CVE-2020-36969: M/Monit 3.7.4 - Privilege Escalation
M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36969?
CVE-2020-36969 has a high severity level due to its ability to allow privilege escalation for authenticated users.
How do I fix CVE-2020-36969?
To fix CVE-2020-36969, it is recommended to update M/Monit to the latest version where the vulnerability is patched.
What kind of attack is possible with CVE-2020-36969?
CVE-2020-36969 allows attackers to escalate privileges by manipulating user permissions via crafted POST requests.
Who is affected by CVE-2020-36969?
CVE-2020-36969 affects users of M/Monit version 3.7.4.
What components of M/Monit are affected by CVE-2020-36969?
CVE-2020-36969 specifically impacts the /api/1/admin/users/update endpoint where user permissions can be altered.