CVE-2024-40531

HIGH

Pantera CRM <402.072 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0037
EPSS Percentile 29.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Published Aug 05, 2024
Tracked Since Feb 18, 2026