An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/fbkcs/CVE-2024-25270 |
History
Fri, 13 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mirapolis
Mirapolis lms |
|
Weaknesses | CWE-639 | |
CPEs | cpe:2.3:a:mirapolis:lms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Mirapolis
Mirapolis lms |
|
Metrics |
cvssV3_1
|
Thu, 12 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Sep 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-12T00:00:00
Updated: 2024-09-12T20:00:30.641Z
Reserved: 2024-02-07T00:00:00
Link: CVE-2024-25270
Vulnrichment
Updated: 2024-09-12T20:00:26.540Z
NVD
Status : Analyzed
Published: 2024-09-12T19:15:03.290
Modified: 2024-09-13T16:01:01.810
Link: CVE-2024-25270
Redhat
No data.