CVE-2024-25270

An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.
References
Link Resource
https://github.com/fbkcs/CVE-2024-25270 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mirapolis:lms:*:*:*:*:*:*:*:*

History

13 Sep 2024, 16:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CWE CWE-639
Summary
  • (es) Un problema en Mirapolis LMS 4.6.XX permite a los usuarios autenticados explotar una vulnerabilidad de Referencia Directa de Objetos Insegura (IDOR) manipulando el parámetro ID y el parámetro STEP de incremento, lo que lleva a la exposición de datos confidenciales del usuario.
References () https://github.com/fbkcs/CVE-2024-25270 - () https://github.com/fbkcs/CVE-2024-25270 - Third Party Advisory
CPE cpe:2.3:a:mirapolis:lms:*:*:*:*:*:*:*:*
First Time Mirapolis lms
Mirapolis

12 Sep 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-12 19:15

Updated : 2024-09-13 16:01


NVD link : CVE-2024-25270

Mitre link : CVE-2024-25270

CVE.ORG link : CVE-2024-25270


JSON object : View

Products Affected

mirapolis

  • lms
CWE
CWE-639

Authorization Bypass Through User-Controlled Key