CVE-2023-27095

MEDIUM

OpenGoofy Hippo4j <1.4.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserController function in Tenant Management module.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory
https://github.com/opengoofy/hippo4j/issues/1061

Scores

CVSS v3 6.5
EPSS 0.0015
EPSS Percentile 35.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (2)
cn.hippo4j/hippo4j-core 0Maven
opengoofy/hippo4j < 1.4.3
Published Mar 16, 2023
Tracked Since Feb 18, 2026