Aller au contenu

Fiche vulnérabilité

CVE-2021-46561 : faille élevée mitre cve services (CVSS 7.2)

Description

controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achieve unintended access within the context of that new organization.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
26 janv. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • mitre cve services

Références

Rechercher une autre vulnérabilité dans la base CVE