IDOR Vulnerability: Allowing Organization Owner to view the other Organizations API KEY and USERS
CVE-2024-25635
8.8HIGH
What is CVE-2024-25635?
The alf.io ticket reservation system presents a security vulnerability that allows organization owners to inadvertently access sensitive information from other organization owners. Specifically, prior to version 2.0-Mr-2402, users can exploit the http://192.168.26.128:8080/admin/api/users/<user_id>
endpoint, which reveals the API KEY and user data associated with a specific user ID. This vulnerability raises significant privacy concerns and emphasizes the necessity for timely updates and secure coding practices.
Affected Version(s)
alf.io < 2.0-M4-2402