CVE-2023-37498

Publication date

2023-08-03 21:34:23

Family

HCL

State

PUBLISHED

Description

A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator.  It is possible that an attacker could potentially escalate their privileges.