PT-2026-82219 · Unknown · Idurar Erp/Crm
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
IDURAR ERP CRM (affected versions not specified)
Description
An issue exists where the system changes the password of any account specified in a request instead of the account making the request. The update handler in
backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves the authenticated user from the token middleware but applies the update based on the identifier provided in the URL path without comparing the two. While the route requires an administrator token, any valid administrator session allows a caller to set an arbitrary password for any other administrator account. Additionally, the read handler in the same controller directory accepts identifiers in the same manner, allowing a user to obtain the necessary identifiers for a target account.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Idurar Erp/Crm