14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.
An attacker sends an HTTP request to the /api/admin/user?id endpoint with the appropriate user identifier, resulting in the user being deleted from the system. The lack of access control mechanisms in handling this request means that the operation can be performed without possessing administrative privileges or any authentication. The vulnerability is remote in nature and requires no interaction from the victim.
An attacker can permanently delete any user accounts in the system, including administrative accounts, leading to loss of data integrity and potential application unavailability. In extreme cases, it is possible to completely deprive all users of system access.
Apply patches available from the manufacturer according to the references. Temporarily, it is recommended to restrict access to the /api/admin/user endpoint at the firewall or reverse proxy level and enforce strong authentication and authorization controls for all API administrative operations.
14Finger version 1.1 (B1Ackc4T product)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HB1ackc4t 14finger
APPB1Ackc4T1.1
Related vulnerabilities
RCE w funkcji fingerprint narzędzia 14Finger v1.1
Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user inf...
Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator...