CPE
medium
advisory
Semaphore UI Cross-Site Request Forgery Vulnerability
2 TTPs 1 CVESemaphore UI is vulnerable to a CSRF attack via the password change endpoint, enabling unauthenticated attackers to hijack user accounts, including administrator accounts, by inducing an authenticated user to visit a malicious webpage.
Semaphore UI
web-vulnerability
csrf
account-takeover
2t
1c
high
advisory
Semaphore UI Privilege Escalation via Custom Role Slug Collision
1 TTP 1 CVESemaphore UI is vulnerable to a privilege escalation where a project manager can create a colliding custom role slug to assign themselves owner-level permissions, bypassing access controls.
Semaphore
privilege-escalation
web-application
cve
1t
1c