CVE-2021-42192
HIGHNuclei
KONGA 0.14.9 - Privilege Escalation
Record summary
CVE-2021-42192 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBKONGA 0.14.9 - Privilege EscalationExploitDB exploitby Fabricio SalomaoNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHKONGA 0.14.9 - Privilege EscalationCVSS 8.8
KONGA 0.14.9 allows attackers to set higher privilege users to full administration access. The attack vector is a crafted condition, as demonstrated by the /api/user/{ID} at ADMIN parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to escalate their privileges and gain unauthorized access to sensitive information or perform unauthorized actions.
Remediation
Upgrade to a patched version of KONGA or apply the necessary security patches provided by the vendor.
WeaknessesCWE-863
Authorsrschio
Template tagscve2021cveauthenticatededbkongaintrusivekonga_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:konga_project:konga:0.14.9:*:*:*:*:*:*:*
http://n0hat.blogspot.com/2021/11/konga-0149-privilege-escalation-exploit.html https://www.exploit-db.com/exploits/50521 https://docs.google.com/document/d/1-YU9zWiDVUps3Mb6zos3996yvZ48vW_vfOvaJLLHc4I/edit?usp=sharing https://github.com/pantsel/konga/
Source: ProjectDiscovery
References
6docs.google.com
https://docs.google.com/document/d/1-YU9zWiDVUps3Mb6zos3996yvZ48vW_vfOvaJLLHc4I/edit?usp=sharing github.com
https://github.com/pantsel/konga github.com
https://github.com/pantsel/konga/commit/d61535277aced18b5be0313ab2d124f60f649978 github.com
https://github.com/whokilleddb/Konga-Privilege-Escalation-Exploit nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-42192 exploit-db.com
https://www.exploit-db.com/exploits/50521