CVE-2024-31525 – Peppermint Ticket Management Privilege Escalation Vulnerability

The following table lists the changes that have been made to the
CVE-2024-31525 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Mar. 05, 2025

    Action Type Old Value New Value
    Added Description Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin and gain complete access to the system as the authorization mechanism is not validated on the server side and only on the client side. This can result, for example, in creating a new admin user in the system which enables persistent access for the attacker as an administrator.
    Added Reference https://cwe.mitre.org/data/definitions/285.html
    Added Reference https://github.com/Peppermint-Lab/peppermint/issues/258
Share the Post:

Related Posts