Q-Free MaxTime Missing Authentication Vulnerability Allowing Arbitrary User Creation
Vulnerability
A vulnerability allowing missing authentication for critical functions has been identified in Q-Free MaxTime versions through 2.11.0. This issue resides in the file maxprofile/accounts/routes.lua and allows unauthenticated remote attackers to create arbitrary users, including those with administrative privileges, by sending crafted HTTP requests.
Impact
Exploitation of this vulnerability allows for the creation of arbitrary user accounts, including administrators, leading to unauthorized access and privilege escalation on the affected system.
Remediation
While an official patch has not been released, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
