High severity8.8NVD Advisory· Published Oct 15, 2024· Updated Jun 17, 2026
CVE-2024-9970
CVE-2024-9970
Description
The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:newtype:flowmaster_bpm_plus:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:newtype:flowmaster_bpm_plus:*:*:*:*:*:*:*:*range: <5.3.1
- (no CPE)
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
2- www.twcert.org.tw/en/cp-139-8137-ea537-2.htmlnvdThird Party Advisory
- www.twcert.org.tw/tw/cp-132-8136-4d5b4-1.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.