An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.
Weakness
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Potential Mitigations
References