Description
The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifying that employee’s ID in the API parameter.
No analysis available yet.
Remediation
Vendor Solution
Update FLYGO to version 1.91.1
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-23789 | The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifying that employee’s ID in the API parameter. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4992-dac66-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T02:41:52.763Z
Reserved: 2021-07-21T00:00:00.000Z
Link: CVE-2021-37215
No data.
Status : Modified
Published: 2021-08-09T10:15:08.503
Modified: 2024-11-21T06:14:52.857
Link: CVE-2021-37215
No data.
OpenCVE Enrichment
No data.
EUVD