Privilege Escalation via Modified Domus and Logged Fields in Comelit App lejos de casa (web) 2.8.0

Privilege Escalation via Modified Domus and Logged Fields in Comelit App lejos de casa (web) 2.8.0

CVE-2019-14453 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus and logged fields, related to js/bridge.min.js and login.json. For example, an attacker can achieve high privileges (installer or administrator) for the graphical interface via a 1C000000000S value for domus, in conjunction with a zero value for logged.

Learn more about our Web App Pen Testing.