templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Reporter | Bluecoat | * | 7.1.1 (including) |