PT-2026-43032 · Outsystems · Outsystems Lifetime
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OutSystems Lifetime versions prior to 11.28.2.3955
Description
An authorization bypass exists where an authenticated user can manipulate the
ApplicationID parameter to gain unauthorized access. This allows the user to read the Change Log, which contains actions performed by other users and the names of any application.Recommendations
Update to version 11.28.2.3955.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Outsystems Lifetime