Record summary

CVE-2021-42192 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBKONGA 0.14.9 - Privilege EscalationExploitDB exploitby Fabricio SalomaoNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHKONGA 0.14.9 - Privilege EscalationCVSS 8.8

KONGA 0.14.9 allows attackers to set higher privilege users to full administration access. The attack vector is a crafted condition, as demonstrated by the /api/user/{ID} at ADMIN parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to escalate their privileges and gain unauthorized access to sensitive information or perform unauthorized actions.

Remediation

Upgrade to a patched version of KONGA or apply the necessary security patches provided by the vendor.

WeaknessesCWE-863
Authorsrschio
Template tagscve2021cveauthenticatededbkongaintrusivekonga_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:konga_project:konga:0.14.9:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

6