Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter.
References
Configurations
No configuration.
History
20 Dec 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-639 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
20 Dec 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-20 16:15
Updated : 2024-12-20 18:15
NVD link : CVE-2024-55471
Mitre link : CVE-2024-55471
CVE.ORG link : CVE-2024-55471
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key