rConfig
cpe:2.3:a:rconfig:rconfig:*:*:*:*:*:*:*
- < 8.2.8
A privilege escalation vulnerability exists in rConfig Core versions prior to 8.2.8. This vulnerability allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. The absence of proper allowlist validation and admin-level authorization checks in the StoreUserRequest component enables attackers to mass-assign the Admin role, granting access to privileged features. rConfig Pro and Enterprise versions are not affected.
Exploitation of this vulnerability allows for unauthorized assignment of the Admin role to users, including the attacker, thereby granting access to sensitive features and functionalities reserved for administrators.
To reproduce this vulnerability, an authenticated user can send a request to the Users API to create a new user or update an existing user's profile. The request must include a role field with the value 'Admin'. Since rConfig Core versions prior to 8.2.8 do not validate the role assignment or require proper authorization, the API will accept the request and assign the Admin role, regardless of the user's actual privileges.
Users can update to rConfig Core version 8.2.8 or later, where this vulnerability has been addressed. Instructions for downloading the latest version are available on the rConfig GitHub repository.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.