{"id":"CVE-2017-7571","details":"public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.","modified":"2026-08-27T08:13:40.439467Z","published":"2017-04-06T17:59:00.240Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/97493"},{"type":"EVIDENCE","url":"http://rungga.blogspot.co.id/2017/04/csrf-privilege-escalation-manipulation.html"},{"type":"EVIDENCE","url":"https://github.com/ladybirdweb/faveo-helpdesk/issues/446"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/41830/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/faveosuite/faveo-helpdesk","events":[{"introduced":"1995c6f22feb3c94a2dd6087db3f484236414189"},{"last_affected":"1995c6f22feb3c94a2dd6087db3f484236414189"}],"database_specific":{"cpe":"cpe:2.3:a:ladybirdweb:faveo_helpdesk:1.9.3:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.9.3"},{"last_affected":"1.9.3"}],"source":"CPE_STRING"}}],"versions":["1.9.3","v1.9.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7571.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}