CVE-2024-55471

MEDIUM

Oqtane.Framework - Insecure Direct Object Reference in UserController via ID Parameter

Title source: llm
STIX 2.1

Description

Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter.

Scores

CVSS v3 6.5
EPSS 0.0034
EPSS Percentile 25.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
nuget/Oqtane.Framework 0NuGet
nuget/Oqtane.Server 0NuGet
Published Dec 20, 2024
Tracked Since Feb 18, 2026