ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.
{ "severity": "High", "cpes": [ "cpe:2.3:a:processmaker:processmaker:*:*:*:*:*:*:*:*" ] }