Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-12048

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints, allowing attackers to view, edit, and delete other users' information without proper authorization. Affected endpoints include but are not limited to /get/project/{project_id}, /get/schedule_data/{agent_id}, /delete/{agent_id}, /get/organisation/{organisation_id}, and /get/user/{user_id}.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:superagi:superagi:0.0.14:*:*:*:*:*:*:*

EPSS

Процентиль: 31%
0.00116
Низкий

8.8 High

CVSS3

Дефекты

CWE-304
CWE-639

Связанные уязвимости

CVSS3: 8.8
github
11 месяцев назад

An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints, allowing attackers to view, edit, and delete other users' information without proper authorization. Affected endpoints include but are not limited to /get/project/{project_id}, /get/schedule_data/{agent_id}, /delete/{agent_id}, /get/organisation/{organisation_id}, and /get/user/{user_id}.

EPSS

Процентиль: 31%
0.00116
Низкий

8.8 High

CVSS3

Дефекты

CWE-304
CWE-639