Privilege Escalation: Read-Only to Admin
High
I
Inflection
Submitted None
Team Summary
Official summary from Inflection
While the interface hides the users page from read-only users, they can still perform PUT requests to the API to change their privileges where they only have read-only permissions.
Actions:
Reported by
foobar7
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Privilege Escalation