An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.
References
Link | Resource |
---|---|
https://github.com/fbkcs/CVE-2024-25270 | Third Party Advisory |
Configurations
History
13 Sep 2024, 16:01
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CWE | CWE-639 | |
Summary |
|
|
References | () https://github.com/fbkcs/CVE-2024-25270 - Third Party Advisory | |
CPE | cpe:2.3:a:mirapolis:lms:*:*:*:*:*:*:*:* | |
First Time |
Mirapolis lms
Mirapolis |
12 Sep 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-12 19:15
Updated : 2024-09-13 16:01
NVD link : CVE-2024-25270
Mitre link : CVE-2024-25270
CVE.ORG link : CVE-2024-25270
JSON object : View
Products Affected
mirapolis
- lms
CWE
CWE-639
Authorization Bypass Through User-Controlled Key