CVE-2023-36646

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/12/2023
Last modified:
13/12/2023

Description

Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve privilege escalation via REST API endpoint invocation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:prolion:cryptospike:3.0.15:p2:*:*:*:*:*:*


References to Advisories, Solutions, and Tools