🟢 Authenticated admin with limited privileges can escalate perms via Framework BMO AJAX dispatcher

Summary

Systems with multiple administrators and delegated control over different modules do not enforce sufficient privilege checks to prevent access to non-delegated module controls.

Authentication with a known user account in a multiple administrator setup is required.

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-pw3c-6wm2-mxg4

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

G - Green

Link to Published GHSA with More Details

Highlights

:green_circle: