{ "id": "CVE-2024-29316", "sourceIdentifier": "cve@mitre.org", "published": "2024-03-28T23:15:46.470", "lastModified": "2024-03-29T06:15:07.460", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via \"isadmin\":true." } ], "metrics": {}, "references": [ { "url": "https://medium.com/%40krityamkarma858041/broken-access-control-nodebb-v3-6-7-eebc59c24deb", "source": "cve@mitre.org" }, { "url": "https://nodebb.org/bounty/", "source": "cve@mitre.org" } ] }