cve/2025/CVE-2025-57396.md
2025-09-29 21:09:30 +02:00

809 B

CVE-2025-57396

Description

Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework of the API, which resulted in the User Profile API Endpoint containing two boolean values indicating whether a user is staff or administrative. Consequently, any user can escalate their privileges to the highest level.

POC

Reference

No PoCs from references.

Github