Home
MEDIUM: 4.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:UDefault status
affected
v4.40.x
unaffected
Description
On a Cryptobox platform where administrator segregation based on entities is used, some vulnerabilities in Ercom Cryptobox administration console allows an authenticated entity administrator with knowledge to elevate his account to global administrator.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CWE-1220: Insufficient Granularity of Access Control
Product status
v4.40.x
References
info.cryptobox.com/doc/v4.40/4.40.en/