Description
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserController function in Tenant Management module.
Remediation
References
https://github.com/opengoofy/hippo4j/issues/1061
Related Vulnerabilities
CVE-2022-22965 Vulnerability in maven package org.springframework.boot:spring-boot-starter-web
CVE-2020-5207 Vulnerability in maven package io.ktor:ktor-server-cio
CVE-2015-0250 Vulnerability in maven package batik:batik-dom
CVE-2020-7788 Vulnerability in npm package ini
CVE-2020-7733 Vulnerability in maven package org.webjars.npm:ua-parser-js