PT-2026-48637 · Cerebrate · Cerebrate
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Cerebrate versions prior to 1.37
Description
An authenticated attacker can perform unauthorized modification of records by supplying the
id primary key field through request input during CRUD edit operations and specific custom entity patching flows. In entities where id is not explicitly marked as inaccessible, a crafted request containing the id of another record causes the save operation to update that unrelated record instead of the one identified by the route parameter. This issue affects entity types with permissive mass-assignment defaults, such as User, Role, UserSetting, LocalTool, PermissionLimitation, and EnumerationCollection. Because the UserSettings edit functionality is accessible to any authenticated user, this can lead to unauthorized record modifications depending on the writable fields and the endpoint used.Recommendations
Update to version 1.37.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cerebrate