CVE-2025-66385
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying role_id or organisation_id fields in the edit request.
Vendor
-
Product
-
CWE
Yayın Tarihi
2025-11-28 07:15:59
Güncelleme
2025-12-01 15:39:33
Source Identifier
cve@mitre.org
KEV Date Added
-