A security flaw has been discovered in Solvait version 24...
Moderate severity
Unreviewed
Published
Oct 7, 2024
to the GitHub Advisory Database
•
Updated Oct 8, 2024
Description
Published by the National Vulnerability Database
Oct 7, 2024
Published to the GitHub Advisory Database
Oct 7, 2024
Last updated
Oct 8, 2024
A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and Action Type parameters in /AssignToMe/SetAction, an attacker can bypass approval workflows leading to unauthorized access to sensitive information or approval of fraudulent requests.
References