Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2024-37769

Disclosure Date: July 05, 2024 (last updated February 26, 2025)
Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.
Attacker Value
Unknown

CVE-2024-37768

Disclosure Date: July 05, 2024 (last updated July 09, 2024)
14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.