[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#Vertical Privilege Escalation

articleCRITICAL 9.1

Vertical Privilege Escalation in praisonai-platform via PATCH /workspaces/{id}/members/{user_id}

A critical vulnerability was discovered in the praisonai-platform, allowing any workspace member to promote themselves or others to an owner via the PATCH /workspaces/{id}/members/{user_id} endpoint. This is due to insufficient role checks and improper use of the require_workspace_member dependency in the route.

Jun 3, 20261 source