CVE-2022-30760

MEDIUM

ihb eG FlexNow <2.04.09.016 - Info Disclosure

Title source: llm
STIX 2.1

Description

An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://wiki.ihb-eg.de/doku.php/releasenotes/fn2web2.04.09

Scores

CVSS v3 4.3
EPSS 0.0013
EPSS Percentile 32.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-639
Status published
Products (1)
ihb-eg/fn2web < 2.04.09.016
Published Jun 09, 2022
Tracked Since Feb 18, 2026