An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-06-09T15:14:10

Updated: 2024-08-03T06:56:14.042Z

Reserved: 2022-05-16T00:00:00

Link: CVE-2022-30760

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-09T16:15:08.870

Modified: 2022-06-17T19:57:09.527

Link: CVE-2022-30760

cve-icon Redhat

No data.