PT-2026-94038 · Metasfresh · Metasfresh
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
metasfresh (affected versions not specified)
Description
The 'DocumentAttachmentsRestController' and 'CommentsRestController' endpoints fail to enforce record-level permissions, verifying only that the user is authenticated. This allows authenticated attackers to enumerate sequential document identifiers to read, replace, or delete attachments and comments associated with records that their assigned role should not be able to access.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metasfresh