Description
The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the bulletin ID in specific Url parameters and access and modify bulletin particular content.
No analysis available yet.
Remediation
Vendor Solution
Update FLYGO to version 1.91.1
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-23786 | The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the bulletin ID in specific Url parameters and access and modify bulletin particular content. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4989-5d955-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T02:06:03.930Z
Reserved: 2021-07-21T00:00:00.000Z
Link: CVE-2021-37212
No data.
Status : Modified
Published: 2021-08-09T10:15:08.277
Modified: 2024-11-21T06:14:52.493
Link: CVE-2021-37212
No data.
OpenCVE Enrichment
No data.
EUVD