CVE-2024-37769
https://notcve.org/view.php?id=CVE-2024-37769
Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request. Los permisos inseguros en 14Finger v1.1 permiten a los atacantes escalar privilegios de usuario normal a administrador mediante una solicitud POST manipulada. • https://github.com/b1ackc4t/14Finger/issues/12 • CWE-278: Insecure Preserved Inherited Permissions •
CVE-2024-37768
https://notcve.org/view.php?id=CVE-2024-37768
14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id. Se descubrió que 14Finger v1.1 contenía una vulnerabilidad de eliminación arbitraria de usuarios a través del componente /api/admin/user?id. • https://github.com/b1ackc4t/14Finger/issues/12 •