An API endpoint that should be limited to web application...
Moderate severity
Unreviewed
Published
Jul 29, 2025
to the GitHub Advisory Database
•
Updated Jul 29, 2025
Description
Published by the National Vulnerability Database
Jul 29, 2025
Published to the GitHub Advisory Database
Jul 29, 2025
Last updated
Jul 29, 2025
An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used to import the appliance configuration, allowing an attacker to control the configuration of the appliance, to include granting themselves administrative level permissions.
References