An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://ibb.co/Pt9qd8t | exploit |
https://ibb.co/JKh4hmD | exploit |
https://ibb.co/rfrKj3r | exploit |
https://ibb.co/hLLPTVp | exploit |
https://github.com/shenhav12/CVE-2024-25169-Mezzanine-v6.0.0 | third party advisory |