PT-2026-77025 · Netiket Information Technologies · Edoweb
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
EdoWEB versions prior to 780-g7
Description
An authorization bypass exists in Netiket Information Technologies EdoWEB due to a user-controlled key, which allows access to functionality that is not properly constrained by Access Control Lists (ACLs). ACLs are security mechanisms used to define which users or system processes are granted access to specific objects.
Recommendations
Update EdoWEB to version 780-g7 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edoweb