CVE-2019-14347
HIGHSchben Adive < 2.0.7 - Privilege Escalation via User Addition
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-14347. PoCs published by Pablo Santiago.
AI-analyzed exploit summary This exploit demonstrates a privilege escalation vulnerability in Adive Framework 2.0.7 by allowing an authenticated user to create a new user with elevated permissions. The script logs in with provided credentials and sends a crafted POST request to add a new user with specified permissions.
Description
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script.
Exploits (1)
This exploit demonstrates a privilege escalation vulnerability in Adive Framework 2.0.7 by allowing an authenticated user to create a new user with elevated permissions. The script logs in with provided credentials and sends a crafted POST request to add a new user with specified permissions.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H