CVE-2024-55186

MEDIUM

Nuget Oqtane.framework - IDOR

Title source: rule
STIX 2.1

Description

An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to access inbox messages of other users by manipulating the notification ID in the request URL. By changing the notification ID, an attacker can view sensitive mail details belonging to other users.

Scores

CVSS v3 4.3
EPSS 0.0008
EPSS Percentile 23.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (4)
nuget/Oqtane.Client 0NuGet
nuget/Oqtane.Framework 0NuGet
nuget/Oqtane.Server 0NuGet
nuget/Oqtane.Shared 0NuGet
Published Dec 20, 2024
Tracked Since Feb 18, 2026