Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Nesilguvenlik

#39164de 53,640
7.1CVSS total
Vulnerabilidades · 1
PT-2026-3484
7.1
2026-01-19
Unknown · Teklifolustur App · CVE-2026-23843
**Name of the Vulnerable Software and Affected Versions** teklifolustur app versions prior to commit dd082a134a225b8dcd401b6224eead4fb183ea1c **Description** teklifolustur app is a web-based PHP application for managing quotes. An Insecure Direct Object Reference (IDOR) exists in the offer view functionality. Authenticated users can manipulate the `offer id` parameter to access offers belonging to other users due to missing authorization checks. The application fails to verify if the requested offer belongs to the currently authenticated user. **Recommendations** Update to commit dd082a134a225b8dcd401b6224eead4fb183ea1c or later.