No analysis available yet.
Vendor Solution
No solution has been reported yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. This allows an authenticated user to modify the information of other registered users. Successful exploitation of this vulnerability allows an authenticated user to modify other users' information, such as their email address, and request a new password via the '/webconnect/#/forgotPassword' endpoint. This could lead to complete account takeover. | |
| Title | Multiple vulnerabilities in MphRx's Minerva | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-04-28T13:45:36.183Z
Reserved: 2026-04-08T08:32:46.515Z
Link: CVE-2026-5779
Updated: 2026-04-28T13:45:33.617Z
Status : Received
Published: 2026-04-28T13:19:22.420
Modified: 2026-04-28T13:19:22.420
Link: CVE-2026-5779
No data.
OpenCVE Enrichment
No data.