CVE-2023-24760: Ofcms Project Ofcms

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.

Affected products

Published 2023-03-16. Last modified 2026-06-17.