Peppermint Ticket Management 0.4.6 is vulnerable to...
High severity
Unreviewed
Published
Mar 5, 2025
to the GitHub Advisory Database
•
Updated Mar 6, 2025
Description
Published by the National Vulnerability Database
Mar 5, 2025
Published to the GitHub Advisory Database
Mar 5, 2025
Last updated
Mar 6, 2025
Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin and gain complete access to the system as the authorization mechanism is not validated on the server side and only on the client side. This can result, for example, in creating a new admin user in the system which enables persistent access for the attacker as an administrator.
References