CVE-2021-37214
HIGHFlygo - Privilege Escalation
Title source: llmDescription
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.
Scores
CVSS v3
8.8
EPSS
0.0057
EPSS Percentile
68.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-639
CWE-706
Status
published
Affected Products (1)
larvata/flygo
< 1.91.1
Timeline
Published
Aug 09, 2021
Tracked Since
Feb 18, 2026