Lucene search

K
cvelistMitreCVELIST:CVE-2021-26594
HistoryFeb 23, 2021 - 6:59 p.m.

CVE-2021-26594

2021-02-2318:59:27
mitre
www.cve.org
8
directus
privilege escalation
vulnerability
unsupported products

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

44.2%

In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

44.2%

Related for CVELIST:CVE-2021-26594