Pat Infinite Solutions HelpdeskAdvanced
cpe:2.3:a:zucchetti:helpdeskadvanced:*:*:*:*:*:*:*
- <= 11.0.33
A vulnerability allowing low privileged users to edit their own Access Control List (ACL) rules has been identified in Pat Infinite Solutions HelpdeskAdvanced versions 11.0.33 and prior. This issue arises from incorrect access control, which enables users to send requests to the 'AclList/SaveAclRules' administrative function and modify their ACL rules.
Exploitation of this vulnerability could lead to unauthorized modifications of ACL rules, allowing users to potentially escalate privileges or gain unauthorized access to certain functionalities or data.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.