Vulnerability Description
An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.
CVSS Score
6.3
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ellevo | Ellevo | 6.2.0.38160 |
Related Weaknesses (CWE)
References
- https://csflabs.github.io/cve/2024/09/06/cve-2024-42759-approval-of-your-own-ticExploitThird Party Advisory
- https://ellevo.com/Product
FAQ
What is CVE-2024-42759?
CVE-2024-42759 is a vulnerability with a CVSS score of 6.3 (MEDIUM). An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.
How severe is CVE-2024-42759?
CVE-2024-42759 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-42759?
Check the references section above for vendor advisories and patch information. Affected products include: Ellevo Ellevo.