VDB
Sign up
MEDIUM6.5

GHSA-hhcw-wwxv-g95c

Oqtane Framework Insecure Direct Object Reference vulnerability

Details

Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/Oqtane.Framework
Introduced in: 0

No fixed version published yet for Oqtane.Framework (nuget). Pin to a known-safe version or switch to an alternative.

NuGet/Oqtane.Server
Introduced in: 0

No fixed version published yet for Oqtane.Server (nuget). Pin to a known-safe version or switch to an alternative.

References