PT-2026-97344 · Unknown · Webcon Bps
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
WEBCON BPS versions prior to 2025.2.1.177
WEBCON BPS versions prior to 2026.1.1.20
Description
An Insecure Direct Object Reference (IDOR) exists in the '/api/vacations/{path}' endpoint. The Gantt vacation chart API fails to validate if the requesting user is authorized to access data for the users specified in the
selectedPeople parameter. An authenticated attacker can provide arbitrary user logins in the selectedPeople parameter to view the vacation schedules of other employees, including managers and staff from different offices, bypassing business logic access restrictions and leading to the unauthorized disclosure of sensitive scheduling information.Recommendations
Update to version 2025.2.1.177.
Update to version 2026.1.1.20.
As a temporary mitigation, restrict access to the '/api/vacations/{path}' endpoint or avoid using the
selectedPeople parameter until the updates are applied.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webcon Bps