ZeroHour

CVE-2021-37214

CVSS 3.1
8.8 high
EPSS
1%p63
Published
()
Modified
Description

The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.

Vendors
larvata
Products
flygo
Weakness
CWE-706, CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.