VYPR
High severity8.8OSV Advisory· Published Sep 21, 2024· Updated Apr 15, 2026

CVE-2024-47210

CVE-2024-47210

Description

Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Gladysassistant/GladysOSV2 versions
    v2.1.0, v2.1.1, v2.1.3, …+ 1 more
    • (no CPE)range: v2.1.0, v2.1.1, v2.1.3, …
    • (no CPE)range: <4.45.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.