CVE-2024-55471
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/12/2024
Last modified:
20/12/2024
Description
Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



