{ "id": "CVE-2024-40531", "sourceIdentifier": "cve@mitre.org", "published": "2024-08-05T16:15:36.800", "lastModified": "2024-08-06T16:30:24.547", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "An issue in UAB Lexita PanteraCRM CMS v.401.152 and Patera CRM CMS v.402.072 allows a remote attacker to escalate privileges via the user profile management function." }, { "lang": "es", "value": "Un problema en UAB Lexita PanteraCRM CMS v.401.152 y Patera CRM CMS v.402.072 permite a un atacante remoto escalar privilegios a trav\u00e9s de la funci\u00f3n de gesti\u00f3n de perfiles de usuario." } ], "metrics": {}, "references": [ { "url": "https://critical.lt/blog/authorization-bypass-and-mass-assignment-in-pantera-crm/", "source": "cve@mitre.org" } ] }