Aller au contenu

Fiche vulnérabilité

CVE-2021-37214 : faille élevée Larvata Digital Technology Co. Ltd… (CVSS 8.8)

Description

The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
9 août 2021
Dernière mise à jour
17 sept. 2024

Produits concernés

  • Larvata Digital Technology Co. Ltd. FLYGO

Correctif et mesures

Update FLYGO to version 1.91.1

Références

Rechercher une autre vulnérabilité dans la base CVE