PT-2026-70144 · Unknown · Idurar Erp/Crm
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Idurar IDURAR ERP CRM version 4.1.0
Description
A broken access control issue allows unauthenticated remote attackers to download invoice PDF files containing customer personally identifiable information (PII). This occurs because the '/download' router is mounted without authentication middleware, leaving it publicly accessible. An attacker can enumerate MongoDB ObjectIds to retrieve any invoice stored in the system without providing credentials.
Recommendations
Update Idurar IDURAR ERP CRM version 4.1.0 to a version that implements proper authentication middleware for the '/download' router.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Idurar Erp/Crm