CVE-2021-37214

HIGH

Flygo - Privilege Escalation

Title source: llm

Description

The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.

Scores

CVSS v3 8.8
EPSS 0.0057
EPSS Percentile 68.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-639 CWE-706
Status published

Affected Products (1)

larvata/flygo < 1.91.1

Timeline

Published Aug 09, 2021
Tracked Since Feb 18, 2026