ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.
{
"cpes": [
"cpe:2.3:a:processmaker:processmaker:*:*:*:*:*:*:*:*"
],
"severity": "High"
}