CVE-2022-38577EPSS p72.8%

CVE-2022-38577CVE-2022-38577

processmaker / processmaker

Description

ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.

Scoring

CVSS 8.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS1.54% probability of exploitation · percentile 72.8% · 2026-08-18T12:04:07Z
Last modified2026-07-09
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.