漏洞标题
H6Web中存在的不安全直接对象引用(IDOR)漏洞
漏洞描述信息
在Anapi Group的h6web中存在不安全直接对象引用(IDOR)漏洞,允许经过身份验证的攻击者通过发送POST请求并修改“/h6web/ha_datos_hermano.php”端点中的“pkrelated”参数来访问其他用户的信息。此外,首次请求还可能使攻击者冒充其他用户。因此,利用IDOR漏洞后发出的所有请求都将使用被冒充用户的权限执行。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
漏洞类别
通过用户控制密钥绕过授权机制
漏洞标题
Insecure direct object reference (IDOR) vulnerability in H6Web
漏洞描述信息
Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by making a POST request and modifying the “pkrelated” parameter in the “/h6web/ha_datos_hermano.php” endpoint to refer to another user. In addition, the first request could also allow the attacker to impersonate other users. As a result, all requests made after exploitation of the IDOR vulnerability will be executed with the privileges of the impersonated user.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
漏洞类别
通过用户控制密钥绕过授权机制