UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leading to privilege escalation and remote code execution.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.019}

epss

{'score': 0.01805}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-04-11T16:16:21

Updated: 2024-08-05T10:47:04.176Z

Reserved: 2018-09-21T00:00:00

Link: CVE-2018-17305

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-04-11T17:29:00.227

Modified: 2024-11-21T03:54:12.433

Link: CVE-2018-17305

cve-icon Redhat

No data.