Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2022-24450 |
CWE-ID | CWE-863 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
Beego Web applications / Modules and components for CMS |
Vendor | beego Framework |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU64698
Risk: Medium
CVSSv4.0: 6.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-24450
CWE-ID:
CWE-863 - Incorrect Authorization
Exploit availability: No
DescriptionThe vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to misusing the "dynamically provisioned sandbox accounts" feature. A remote user can take advantage of its valid account and switch over to another existing account without further authentication to obtain the privileges of the System account.
Install update from vendor's website.
Vulnerable software versionsBeego: 2.0.0 - 2.0.6
CPE2.3http://github.com/beego/beego/releases/tag/v2.0.7
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.