Insecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an authenticated user with low privileges to enumerate and access tenant information belonging to other clients via modification of the tenant ID in the request URL.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an authenticated user with low privileges to enumerate and access tenant information belonging to other clients via modification of the tenant ID in the request URL. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-29T18:47:48.765Z
Reserved: 2025-10-03T00:00:00.000Z
Link: CVE-2025-61876
No data.
Status : Received
Published: 2025-10-29T19:15:38.330
Modified: 2025-10-29T19:15:38.330
Link: CVE-2025-61876
No data.
OpenCVE Enrichment
No data.