CVE-2019-11218

Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenticated users to gain application administrator privileges via additional form parameter submissions.
References
Link Resource
https://flab.cesnet.cz/advisories/cve-2019-11218 Third Party Advisory
https://bonobogitserver.com/changelog/#version-650 Release Notes Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:bonobogitserver:bonobo_git_server:*:*:*:*:*:*:*:*

Information

Published : 2019-04-24 08:29

Updated : 2021-07-21 11:39


NVD link : CVE-2019-11218

Mitre link : CVE-2019-11218

Products Affected
No products.
CWE