First published: Thu Aug 03 2023(Updated: )
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It is possible that an attacker could potentially escalate their privileges.
Credit: psirt@hcl.com psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Unica | <12.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37498 is a vulnerability that allows a user to assign themselves to arbitrary groups by reusing a POST request issued by an administrator, potentially leading to privilege escalation.
CVE-2023-37498 has a severity score of 8.1 out of 10, indicating a high severity.
The Hcltech Unica software version 12.1.1 is affected by CVE-2023-37498.
An attacker can exploit CVE-2023-37498 by reusing a POST request issued by an administrator to assign themselves to arbitrary groups, potentially escalating their privileges.
To fix CVE-2023-37498, apply the latest security updates provided by Hcltech for the Unica software version 12.1.1.