KONGA 0.14.9 allows attackers to set higher privilege users to full administration access. The attack vector is a crafted condition, as demonstrated by the /api/user/{ID} at ADMIN parameter.Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view