CyberRota Analysis
AI-GeneratedA horizontal privilege escalation vulnerability allows authenticated users of x-ui 0.3.2 to alter the inbound proxy configurations of other users, including critical settings such as ports and traffic quotas. This flaw arises from the system's failure to verify the ownership of the target resource, enabling unauthorized data modifications across user sessions. Organizations using this software should prioritize remediation to prevent potential abuse of user configurations and maintain data integrity.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic quota, by submitting a request referencing the target resource identifier. The update path fails to verify that the target resource belongs to the requesting session user, allowing unauthorized cross-user modification of data.