CVE-2024-7473
MEDIUMLunary Evaluations - Insecure Direct Object Reference Prompt Update
Title source: manualDescription
An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' parameter in the request. The issue is fixed in version 1.4.3.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/afecd927-b5f6-44ba-9147-5c45091beda5
Scores
CVSS v3
6.5
EPSS
0.0043
EPSS Percentile
34.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
lunary/lunary
1.3.2
Published
Oct 29, 2024
Tracked Since
Feb 18, 2026