blog.cybelesoft.com
https://blog.cybelesoft.com/thinfinity-workspace-security-bulletin-nov-2024 CVE-2024-40408
HIGH
Record summary
CVE-2024-40408 has a selected CVSS score of 7.3 (high).
Description
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 25, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
thinfinity_workspaceBrowse cybelesoft / thinfinity_workspaceDefault status: unknown | CVE List | Before 7.0.2.113 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-40408