ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.
{ "cpes": [ "cpe:2.3:a:processmaker:processmaker:*:*:*:*:*:*:*:*" ], "severity": "High" }