CVE-2021-47701
HIGHOpenBMCS 2.4 - Privilege Escalation via User Permissions Update Script
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47701. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates a privilege escalation vulnerability in OpenBMCS 2.4, allowing a regular user to elevate their permissions or create administrative users via HTTP POST requests to specific PHP scripts.
Description
OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and exploiting a vulnerability in the update_user_permissions.php script. Attackers can submit a malicious HTTP POST request to PHP scripts in '/plugins/useradmin/' directory.
Exploits (1)
This exploit demonstrates a privilege escalation vulnerability in OpenBMCS 2.4, allowing a regular user to elevate their permissions or create administrative users via HTTP POST requests to specific PHP scripts.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H