UsersController::edit in Cerebrate before 1.30 allows an...
Critical severity
Unreviewed
Published
Nov 28, 2025
to the GitHub Advisory Database
•
Updated Nov 28, 2025
Description
Published by the National Vulnerability Database
Nov 28, 2025
Published to the GitHub Advisory Database
Nov 28, 2025
Last updated
Nov 28, 2025
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying role_id or organisation_id fields in the edit request.
References