Remote User Can Obtain Purchased Ticket Download URL
CVE-2024-4537
7.5HIGH
What is CVE-2024-4537?
The Janto Ticketing Software presents a significant security vulnerability characterized by an Insecure Direct Object Reference (IDOR). This flaw exists in version 4.3r10 and enables a remote attacker to retrieve the download URL of another user's purchased ticket. Such exposure can lead to unauthorized access to sensitive user data, potentially compromising the user experience and integrity of the ticketing process. Organizations utilizing this software should prioritize remediation of this vulnerability to safeguard against unauthorized data access.
Affected Version(s)
Janto Ticketing Software 4.3r10.cks