First published: Fri Oct 25 2024(Updated: )
OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is required with OE_ADMIN role privilege.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ovaledge | <=5.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30356 is classified as a privilege escalation vulnerability.
To fix CVE-2022-30356, upgrade to OvalEdge version 5.2.8.1 or later.
CVE-2022-30356 allows authenticated users with OE_ADMIN role to escalate privileges by manipulating user role assignments.
All users running OvalEdge 5.2.8.0 or earlier versions are affected by CVE-2022-30356.
Yes, exploitation of CVE-2022-30356 requires authentication with OE_ADMIN role privileges.