First published: Mon Aug 12 2024(Updated: )
An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OWASP DefectDojo | <1.5.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48171 is classified as a high severity vulnerability due to the potential for privilege escalation.
To fix CVE-2023-48171, update OWASP DefectDojo to version 1.5.3.1 or later.
An attacker can exploit CVE-2023-48171 to escalate user privileges and gain unauthorized access to sensitive functionalities.
CVE-2023-48171 affects all versions of OWASP DefectDojo prior to 1.5.3.1.
Yes, if exploited, CVE-2023-48171 can lead to unauthorized access and potentially result in data breaches.