Description
An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.
References (1)
Core 1
Core References
Scores
CVSS v3
7.5
EPSS
0.0101
EPSS Percentile
77.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
floorsightsoftware/customer_portal
< q3_2023
Published
Jan 02, 2024
Tracked Since
Feb 18, 2026