{ "id": "CVE-2024-29316", "sourceIdentifier": "cve@mitre.org", "published": "2024-03-28T23:15:46.470", "lastModified": "2024-03-29T12:45:02.937", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via \"isadmin\":true." }, { "lang": "es", "value": "NodeBB 3.6.7 es vulnerable a un control de acceso incorrecto; por ejemplo, un atacante con pocos privilegios puede acceder a las pesta\u00f1as restringidas del grupo de administraci\u00f3n a trav\u00e9s de \"isadmin\":true." } ], "metrics": {}, "references": [ { "url": "https://medium.com/%40krityamkarma858041/broken-access-control-nodebb-v3-6-7-eebc59c24deb", "source": "cve@mitre.org" }, { "url": "https://nodebb.org/bounty/", "source": "cve@mitre.org" } ] }