CVE-2024-40408

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:cybelesoft:thinfinity_workspace:*:*:*:*:*:*:*:*

History

01 May 2025, 14:24

Type Values Removed Values Added
References () https://blog.cybelesoft.com/thinfinity-workspace-security-bulletin-nov-2024/ - () https://blog.cybelesoft.com/thinfinity-workspace-security-bulletin-nov-2024/ - Vendor Advisory
First Time Cybelesoft
Cybelesoft thinfinity Workspace
CPE cpe:2.3:a:cybelesoft:thinfinity_workspace:*:*:*:*:*:*:*:*

13 Nov 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-13 23:15

Updated : 2025-05-01 14:24


NVD link : CVE-2024-40408

Mitre link : CVE-2024-40408


JSON object : View

Products Affected

cybelesoft

  • thinfinity_workspace
CWE

No CWE.