Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to change passwords of all other users including administrators leading to a privilege escalation.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://cert.pl/posts/2023/10/CVE-2023-4997/ | third party advisory |
https://cert.pl/en/posts/2023/10/CVE-2023-4997/ | third party advisory |