Home
Description
Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.
References
github.com/GladysAssistant/Gladys/compare/v4.45.0...v4.45.1
github.com/GladysAssistant/Gladys/pull/2115
github.com/...ommit/344ad9b8ca3078d9292dd95f2dd7b9172bc6ebbe