High severity8.1NVD Advisory· Published Aug 3, 2023· Updated Jun 17, 2026
CVE-2023-37498
CVE-2023-37498
Description
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It is possible that an attacker could potentially escalate their privileges.
Affected products
2- Range: <12.1.1
Patches
Vulnerability mechanics
References
1- support.hcltechsw.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.