An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.
{
"cpe": "cpe:2.3:a:konga_project:konga:0.14.9:-:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.14.9-NA"
}
],
"source": "CPE_FIELD"
}