Retour à la veille

CVE-2026-108740

Publié : 11 octobre 2026
Modifié : 11 octobre 2026
Lien officiel NVD
Score CVSS
8.3
HIGH

Description détaillée

GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

Références et Patchs