Description
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserController function in Tenant Management module.
Remediation
References
https://github.com/opengoofy/hippo4j/issues/1061
Related Vulnerabilities
CVE-2020-7772 Vulnerability in npm package doc-path
CVE-2020-15231 Vulnerability in maven package org.mapfish.print:print-servlet
CVE-2022-24999 Vulnerability in maven package org.webjars.npm:qs
CVE-2021-23518 Vulnerability in npm package cached-path-relative
CVE-2022-29078 Vulnerability in maven package org.webjars.npm:ejs