Peppermint Ticket Management Incorrect Access Control Vulnerability Allowing Privilege Escalation
Vulnerability
A vulnerability in Peppermint Ticket Management version 0.4.6 allows regular registered users to elevate their privileges to admin. This issue arises because the authorization mechanism is only validated on the client side, leaving a gap that can be exploited to gain complete access to the system. An attacker could, for instance, create a new admin user, providing persistent administrative access.
Impact
Exploitation of this vulnerability allows a user to gain administrative privileges, enabling unauthorized access to sensitive data and the ability to disrupt normal system operations, such as corrupting tickets and interfering with established workflows.
Reproduction
To reproduce this vulnerability, log in as a regular user and send a request to create a new admin user, including the desired email and password. Despite receiving a '401 Unauthorized' response, the user is created successfully. Alternatively, the 'PUT' method can be used to directly request a role elevation by sending the low-privileged user JWT and the ID of the user to be promoted.
Remediation
This vulnerability has been fixed in version 0.4.7.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
