HIGH🇵🇱 Wersja polska

CVE-2024-50619

CVSS 8.8v3.1pub. 2026-02-11upd. 2026-02-13

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's accounts by tampering with the client's user id to change their account information. A low-privileged authenticated user can elevate his or her system privileges by modifying the information of a user role that is disabled in the client.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Cipplanner Cipace

    APP
    Cipplanner
    < 9.17
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-11598CRITICAL9.8PL ✓same product

CIPAce 9.1 – nieuwierzytelniony upload i RCE przez plik ASHX

CVE-2020-11597CRITICAL9.8PL ✓same product

SQL Injection bez uwierzytelnienia w CIPPlanner CIPAce 9.1

CVE-2020-11586CRITICAL9.8PL ✓same product

XXE w CIPPlanner CIPAce — nieautoryzowany dostęp przez złośliwe DTD

CVE-2024-50617HIGH7.5same product

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow at...

CVE-2024-50620HIGH8.8same product

Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document man...