HIGH7.5
GHSA-995c-qww8-64fj
Oqtane Framework Incorrect Access Control vulnerability
Details
Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or access restricted data without proper authorization. The lack of server-side validation exacerbates the issue, as the application relies on client-side information for authentication.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/Oqtane.Framework
Introduced in:
0No fixed version published yet for Oqtane.Framework (nuget). Pin to a known-safe version or switch to an alternative.
NuGet/Oqtane.Server
Introduced in:
0No fixed version published yet for Oqtane.Server (nuget). Pin to a known-safe version or switch to an alternative.