OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and exploiting a vulnerability in the update_user_permissions.php script. Attackers can submit a malicious HTTP POST request to PHP scripts in '/plugins/useradmin/' directory.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openbmcs
Openbmcs openbmcs |
|
| Vendors & Products |
Openbmcs
Openbmcs openbmcs |
Tue, 09 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and exploiting a vulnerability in the update_user_permissions.php script. Attackers can submit a malicious HTTP POST request to PHP scripts in '/plugins/useradmin/' directory. | |
| Title | OpenBMCS User Management Privilege Escalation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-09T20:35:24.273Z
Updated: 2025-12-09T21:31:24.386Z
Reserved: 2025-12-05T19:10:29.044Z
Link: CVE-2021-47701
Updated: 2025-12-09T21:31:18.463Z
Status : Received
Published: 2025-12-09T21:15:47.860
Modified: 2025-12-09T21:15:47.860
Link: CVE-2021-47701
No data.