CVE-2024-9970: Newtype Flowmaster Bpm Plus
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.
Affected products
- Newtype Flowmaster Bpm Plus: before 5.3.1 (fixed in 5.3.1)
Published 2024-10-15. Last modified 2026-06-17.