PT-2023-16630 · Bhima · Bhima
Carlos Bello
·
Published
2023-04-05
·
Updated
2025-05-08
·
CVE-2023-0944
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Bhima version 1.27.0
Description
The issue allows an authenticated attacker with regular user permissions to update arbitrary user session data, including
username, email, and password. This is due to the application being vulnerable to Insecure Direct Object Reference (IDOR), which means it does not correctly validate user permissions for certain actions.Recommendations
For Bhima version 1.27.0, consider restricting access to user session data until a patch is available. As a temporary workaround, limit the ability of regular users to update sensitive information such as
username, email, and password.Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bhima