An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to access inbox messages of other users by manipulating the notification ID in the request URL. By changing the notification ID, an attacker can view sensitive mail details belonging to other users.
References
Configurations
No configuration.
History
20 Dec 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-639 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
References | () https://gist.github.com/SmitShah1518/00de9ecc46c1a8e2b189185c9d92afb0 - |
20 Dec 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-20 16:15
Updated : 2024-12-20 21:15
NVD link : CVE-2024-55186
Mitre link : CVE-2024-55186
CVE.ORG link : CVE-2024-55186
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key