info: name: Appsmith - Privilege Escalation author: saikir4n severity: high description: Appsmith contains a privilege escalation vulnerability via the /api/v1/users/invite endpoint that allows an authenticated user to invite a user as Administrator, indicating broken access control. impact: | An authenticated attacker can escalate privileges to Administrator level, gaining full control over the Appsmith instance. remediation: | Update Appsmith to version 1.51.0or later to fix this privilege escalation vulnerability. reference: - https://nvd.nist.gov/vuln/detail/CVE-2024-55963 - https://github.com/appsmithorg/appsmith/security/advisories/GHSA-jxh3-4vp2-vhjx - https://rhinosecuritylabs.com/research/cve-2024-55963-appsmith-rce/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H cvss-score:8.8 cve-id: CVE-2024-55963 cwe-id: CWE-269 metadata: verified:true max-request:1 vendor: appsmith product: appsmith shodan-query: http.title:"appsmith" fofa-query: title="appsmith" tags: cve,cve2024,appsmith,privilege-escalation