Improper Authorization in Mendix Applications using Mendix 8 and Mendix Applications using Mendix 9 - CVE-2021-42025
Published: November 18, 2021
Mendix Applications using Mendix 8
Mendix Applications using Mendix 9
Siemens
Description
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to applications built with affected versions of Mendix Studio Pro do not properly control write access for certain client actions. A remote authenticated attacker can manipulate the content of specific objects regardless of whether they have write access.