CVE-2024-57336
MEDIUMM2Soft CROWNIX Report & ERS <7.4.3.599, <8.0.3.79 - Privilege Escal...
Title source: llmDescription
Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unauthorized attackers to obtain Administrator account access.
References (1)
Core 1
Core References
Various Sources
https://www.m2soft.co.kr/sub/board/news.asp?mode=view&idx=2411
Scores
CVSS v3
6.5
EPSS
0.0020
EPSS Percentile
10.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-284
Status
published
Published
May 28, 2025
Tracked Since
Feb 18, 2026