PT-2024-36490 · Unknown · Oqtane Framework

Smitshah1518

·

Published

2024-12-20

·

Updated

2024-12-20

·

CVE-2024-55186

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions oqtane Framework version 6.0.0
Description An IDOR (Insecure Direct Object Reference) issue exists, allowing a logged-in user to access inbox messages of other users by manipulating the notification ID in the request URL. By changing the notification ID, an attacker can view sensitive mail details belonging to other users.
Recommendations For oqtane Framework version 6.0.0, consider restricting access to the inbox messages feature until a patch is available, or implement additional validation to ensure that users can only access their own inbox messages. As a temporary workaround, avoid using the notification ID in the affected API endpoint until the issue is resolved.

Exploit

Fix

Incorrect Authorization

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-55186
GHSA-2HR5-CVWP-JR5W

Affected Products

Oqtane Framework