Sploitus

CVE-2013-2113

4 known exploits for CVE-2013-2113

The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.

Affected products
Foreman
Redhat Openstack
= 3.0
Theforeman Foreman
≤ 1.2.0, 1.1
Fix
Available
CVSS 2.0
6.0 MEDIUM
EPSS
20.9% (97th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2013-07-31
CVE-2013-2113 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2013-2113

Proof-of-concept code and exploit modules indexed by Sploitus