Vulnerabilities > CVE-2023-26987 - Unspecified vulnerability in Konga Project Konga 0.14.9

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
konga-project

Summary

An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

Vulnerable Configurations

Part Description Count
Application
Konga_Project
1