{"id":"CVE-2018-20301","aliases":["GHSA-mrq8-53r4-3j5m"],"url":"https://o3.security/vulnerability/CVE-2018-20301","summary":"Permissive parameters and privilege escalation","details":"An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, \"registration\" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request.","published":"2018-12-20T09:29:00.243Z","modified":"2026-07-08T18:17:50.968116Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.00875,"percentile":0.55809,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Hex","name":"coherence","fixedVersion":"0.5.2"}],"fix":null,"references":[{"type":"REPORT","url":"https://github.com/smpallen99/coherence/issues/270"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T18:17:50.968116Z"}}