CVE
- Id
- 55558
- CVE No.
- CVE-2012-2315
- Status
- Candidate
- Description
- admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.
- Phase
- Assigned (20120419)
- Votes
- None (candidate not yet proposed)
- Comments