CVE

Id
55558  
CVE No.
CVE-2012-2315  
Status
Candidate  
Description
admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.  
Phase
Assigned (20120419)  
Votes
None (candidate not yet proposed)  
Comments