GHSA-q537-qhj4-wcjxHighCVSS 7.2
OpenCTI: Privilege escalation via graphQL API is abusable by organization admins, due to incorrect ACL on userEdit relationAdd
🔗 CVE IDs covered (1)
📋 Description
Summary
An organization admin can escalate their privileges by adding a user from a different organization with higher privileges, to their own organization.
Impact
Full platform access, access to sensitive or proprietary information.
🎯 Affected products1
- pip/pycti:>= 0, < 6.9.7