KONGA 0.14.9 allows attackers to set higher privilege users to full administration access. The attack vector is a crafted condition, as demonstrated by the /api/user/{ID} at ADMIN parameter.
id: CVE-2021-42192
info:
name: KONGA 0.14.9 - Privilege Escalation
author: rschio
severity: h
...