CVE-2024-55186
CVE-2024-55186
Título es
CVE-2024-55186
Vie, 20/12/2024 – 16:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-55186
Descripción en
An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to access inbox messages of other users by manipulating the notification ID in the request URL. By changing the notification ID, an attacker can view sensitive mail details belonging to other users.
20/12/2024
20/12/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off
