CVE-2024-55471

MEDIUM

Nuget Oqtane.framework - IDOR

Title source: rule
STIX 2.1

Description

Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter.

Scores

CVSS v3 6.5
EPSS 0.0009
EPSS Percentile 25.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
nuget/Oqtane.Framework 0NuGet
nuget/Oqtane.Server 0NuGet
Published Dec 20, 2024
Tracked Since Feb 18, 2026