CVE-2024-49376 - Autolab Reset Password Privilege Escalation Vulnerability

1 month ago 8
ARTICLE AD BOX
CVE ID : CVE-2024-49376
Published : Oct. 25, 2024, 1:15 p.m. | 24 minutes ago
Description : Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by resetting their passwords. This issue is fixed in version 3.0.1. No known workarounds exist.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article