Vulnerability Description
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cybelesoft | Thinfinity Workspace | < 7.0.2.113 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-40408?
CVE-2024-40408 is a vulnerability with a CVSS score of 7.3 (HIGH). Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user pro...
How severe is CVE-2024-40408?
CVE-2024-40408 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-40408?
Check the references section above for vendor advisories and patch information. Affected products include: Cybelesoft Thinfinity Workspace.