PT-2026-102910 · Unknown · Kitchenasty
CVSS v3.1
4.3
Medium
| Vector | AC:L/AV:N/A:N/C:L/I:N/PR:L/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
KitchenAsty versions prior to 0.3.1
Description
Broken object level authorization (IDOR) exists in the reservations API. The endpoint 'GET /api/reservations/:id' in packages/server uses authentication middleware but fails to perform ownership or role checks. Consequently, the
getReservation() handler in packages/server/src/controllers/reservation.controller.ts returns records based on the client-supplied :id without verifying if the customerId of the reservation matches the authenticated user.Recommendations
Update KitchenAsty to a version newer than 0.3.0.
As a temporary mitigation, restrict access to the 'GET /api/reservations/:id' endpoint.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kitchenasty