Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wggx-hgvj-qqm8

Опубликовано: 07 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3

Описание

Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Research Infrastructure (BBMRI-ERIC). This vulnerability allows an attacker to access or modify unauthorised resources by manipulating requests that use the 'userID' parameter in '/api/v3/users/', which may result in the exposure or alteration of sensitive data

Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Research Infrastructure (BBMRI-ERIC). This vulnerability allows an attacker to access or modify unauthorised resources by manipulating requests that use the 'userID' parameter in '/api/v3/users/', which may result in the exposure or alteration of sensitive data

EPSS

Процентиль: 23%
0.00074
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-639

Связанные уязвимости

nvd
4 месяца назад

Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Research Infrastructure (BBMRI-ERIC). This vulnerability allows an attacker to access or modify unauthorised resources by manipulating requests that use the 'userID' parameter in '/api/v3/users/<userID>', which may result in the exposure or alteration of sensitive data

EPSS

Процентиль: 23%
0.00074
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-639