PT-2024-36526 · Unknown · Oqtane Framework

Published

2024-12-20

·

Updated

2024-12-20

·

CVE-2024-55471

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oqtane Framework (affected versions not specified)
Description The issue is related to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController, allowing unauthorized users to access sensitive information of other users by manipulating the id parameter.
Recommendations As a temporary workaround, consider restricting access to the Oqtane.Controllers.UserController to minimize the risk of exploitation. Avoid using the id parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-55471
GHSA-HHCW-WWXV-G95C

Affected Products

Oqtane Framework