Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-527r-mrh4-wx97

Опубликовано: 17 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.

An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.

EPSS

Процентиль: 23%
0.00078
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-706

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 года назад

An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.

EPSS

Процентиль: 23%
0.00078
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-706