PT-2024-36490 · Unknown · Oqtane Framework
Smitshah1518
·
Published
2024-12-20
·
Updated
2024-12-20
·
CVE-2024-55186
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
oqtane Framework version 6.0.0
Description
An IDOR (Insecure Direct Object Reference) issue exists, allowing a logged-in user to access inbox messages of other users by manipulating the
notification ID in the request URL. By changing the notification ID, an attacker can view sensitive mail details belonging to other users.Recommendations
For oqtane Framework version 6.0.0, consider restricting access to the inbox messages feature until a patch is available, or implement additional validation to ensure that users can only access their own inbox messages. As a temporary workaround, avoid using the
notification ID in the affected API endpoint until the issue is resolved.Exploit
Fix
Incorrect Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oqtane Framework