Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.
The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://huntr.dev/bounties/0f35b1d3-56e6-49e4-bc5a-830f52e094b3 | exploit third party advisory patch |
https://github.com/polonel/trudesk/commit/83fd5a89319ba2c2f5934722e39b08aba9b3a4ac | third party advisory patch |