Description
Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.
Problem types
CWE-602 Client-Side Enforcement of Server-Side Security
Product status
Any version before v1.10.00.005
Credits
Michael Heinzl reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-24-074-12