An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.
References
History

Fri, 13 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mirapolis
Mirapolis lms
Weaknesses CWE-639
CPEs cpe:2.3:a:mirapolis:lms:*:*:*:*:*:*:*:*
Vendors & Products Mirapolis
Mirapolis lms
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Thu, 12 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Sep 2024 18:45:00 +0000

Type Values Removed Values Added
Description An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-09-12T00:00:00

Updated: 2024-09-12T20:00:30.641Z

Reserved: 2024-02-07T00:00:00

Link: CVE-2024-25270

cve-icon Vulnrichment

Updated: 2024-09-12T20:00:26.540Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-12T19:15:03.290

Modified: 2024-09-13T16:01:01.810

Link: CVE-2024-25270

cve-icon Redhat

No data.