IDOR Vulnerability in CodeAstro's Complaint Management System
CVE-2024-55506

8.8HIGH

Key Information:

Vendor

CodeAstro

Vendor
CVE Published:
18 December 2024

What is CVE-2024-55506?

CVE-2024-55506 is a critical security vulnerability identified as an Insecure Direct Object Reference (IDOR) in CodeAstro's Complaint Management System version 1.0. This flaw allows attackers to manipulate the 'id' parameter in DELETE requests sent to delete.php, enabling them to execute arbitrary code. As a result, unauthorized access to sensitive information may occur, posing a significant risk to users and organizations utilizing the software. Immediate mitigation steps and updates are crucial to safeguard against potential exploitation.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-55506 : IDOR Vulnerability in CodeAstro's Complaint Management System