CVE-2021-33718

CVE-2021-33718

Vendor Siemens
Product Mendix Applications using Mendix 7
Weakness CWE-863 · Incorrect authorization
Published July 13, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.22), Mendix Applications using Mendix 8 (All versions < V8.18.7), Mendix Applications using Mendix 9 (All versions < V9.3.0). Write access checks of attributes of an object could be bypassed, if user has a write permissions to the first attribute of this object.

Key dates

02Disclosure timeline

July 13, 2021 CVE published
August 3, 2024 Record updated