CVE-2024-12125
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-11-06
Last updated on: 2025-11-14
Assigner: Red Hat, Inc.
Description
Description
A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| redhat | 3scale_developer_portal | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-281 | The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a flaw in the 3scale developer portal that allows attackers to create or update accounts by manipulating hidden or read-only fields. These fields can be altered to access or modify restricted information that should not be accessible or changeable by the attacker.
How can this vulnerability impact me? :
The vulnerability can allow an attacker to gain unauthorized access to restricted information or modify it, potentially leading to data breaches or unauthorized changes within the 3scale developer portal.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70