Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-4962

Опубликовано: 18 авг. 2025
Источник: nvd
CVSS3: 7.7
EPSS Низкий

Описание

An Insecure Direct Object Reference (IDOR) vulnerability was identified in the POST /v1/templates endpoint of the Lunary API, affecting versions up to 0.8.8. This vulnerability allows authenticated users to create templates in another user's project by altering the projectId query parameter. The root cause of this issue is the absence of server-side validation to ensure that the authenticated user owns the specified projectId. The vulnerability has been addressed in version 1.9.23.

EPSS

Процентиль: 8%
0.00028
Низкий

7.7 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.7
github
6 месяцев назад

An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Lunary API, affecting versions up to 0.8.8. This vulnerability allows authenticated users to create templates in another user's project by altering the `projectId` query parameter. The root cause of this issue is the absence of server-side validation to ensure that the authenticated user owns the specified `projectId`. The vulnerability has been addressed in version 1.9.23.

EPSS

Процентиль: 8%
0.00028
Низкий

7.7 High

CVSS3

Дефекты

CWE-284