CVE-2024-50650

HIGH

python_book 1.0 - Incorrect Authorization via ID Parameter

Title source: llm
STIX 2.1

Description

python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

Scores

CVSS v3 7.5
EPSS 0.0054
EPSS Percentile 41.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
timgreen/python_book 1.0
Published Nov 15, 2024
Tracked Since Feb 18, 2026