CVE-2023-42228

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request to the "AclList/SaveAclRules" administrative function.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:zucchetti:helpdeskadvanced:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-13 22:15

Updated : 2025-04-17 17:43


NVD link : CVE-2023-42228

Mitre link : CVE-2023-42228

CVE.ORG link : CVE-2023-42228


JSON object : View

Products Affected

zucchetti

  • helpdeskadvanced
CWE
CWE-281

Improper Preservation of Permissions