Description
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.
No analysis available yet.
Remediation
Vendor Solution
Update FLYGO to version 1.91.1
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-23788 | The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4991-658b1-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T00:16:52.168Z
Reserved: 2021-07-21T00:00:00.000Z
Link: CVE-2021-37214
No data.
Status : Modified
Published: 2021-08-09T10:15:08.427
Modified: 2024-11-21T06:14:52.737
Link: CVE-2021-37214
No data.
OpenCVE Enrichment
No data.
EUVD