High severity8.8NVD Advisory· Published Sep 21, 2024· Updated Apr 15, 2026
CVE-2024-47210
CVE-2024-47210
Description
Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.
Patches
21f7617c2fb47344ad9b8ca30Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
3News mentions
0No linked articles in our index yet.