CVE Vulnerabilities

CVE-2023-26987

Published: May 01, 2023 | Modified: May 06, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

Affected Software

Name Vendor Start Version End Version
Konga Konga_project 0.14.9 (including) 0.14.9 (including)

References