PT-2023-16630 · Bhima · Bhima

Carlos Bello

·

Published

2023-04-05

·

Updated

2025-05-08

·

CVE-2023-0944

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bhima version 1.27.0
Description The issue allows an authenticated attacker with regular user permissions to update arbitrary user session data, including username, email, and password. This is due to the application being vulnerable to Insecure Direct Object Reference (IDOR), which means it does not correctly validate user permissions for certain actions.
Recommendations For Bhima version 1.27.0, consider restricting access to user session data until a patch is available. As a temporary workaround, limit the ability of regular users to update sensitive information such as username, email, and password.

Exploit

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2023-0944

Affected Products

Bhima