Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update arbitrary user session data such as username, email and password. This is possible because the application is vulnerable to IDOR, it does not correctly validate user permissions with respect to certain actions that can be performed by the user.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Fluid Attacks
Published: 2023-04-05T00:00:00
Updated: 2024-08-02T05:32:45.042Z
Reserved: 2023-02-21T00:00:00
Link: CVE-2023-0944
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-05T20:15:07.527
Modified: 2024-11-21T07:38:09.390
Link: CVE-2023-0944
Redhat
No data.