PT-2026-36213 · Owasp · Defectdojo
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OWAP DefectDojo versions prior to 2.56.0
Description
An issue exists in the Benchmark, Engagement, Product, and Survey components where a manipulation can lead to a remote authorization bypass, allowing an attacker to circumvent access controls.
Recommendations
Update to version 2.56.0.
Exploit
Fix
IDOR
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Defectdojo