Description
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserController function in Tenant Management module.
Remediation
References
https://github.com/opengoofy/hippo4j/issues/1061
Related Vulnerabilities
CVE-2021-43306 Vulnerability in maven package org.webjars.bower:jquery-validation
CVE-2020-7717 Vulnerability in npm package dot-notes
CVE-2018-18950 Vulnerability in maven package org.webjars.bowergithub.kindsoft:kindeditor
CVE-2021-21363 Vulnerability in maven package io.swagger:swagger-generator
CVE-2017-11556 Vulnerability in maven package org.webjars.npm:node-sass