Skip to content

Unauthorized access to view information of other user

Moderate
marcelfolaron published GHSA-3hfj-qcvj-4hx8 Feb 18, 2025

Package

No package listed

Affected versions

<3.3

Patched versions

3.3

Description

Finding Description

Application has functionality for a user to view profile information. It does not have implemented authorisation check for "Host" parameter which allows a user to view profile information of other user by replacing "Host" parameter.

Impact

By exploiting this vulnerability an attacker can able to view profile information (but not anything else or change anything)

Severity

Moderate

CVE ID

No known CVE

Weaknesses

Credits