CVE-2024-50633

Published Jan 16, 2025

Last updated 9 days ago

Overview

Description
A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users retrieve certain information about other user accounts (this functionality is, in the current design, not restricted to any privileged roles such as event organizer).
Source
cve@mitre.org
NVD status
Awaiting Analysis
CNA Tags
disputed

Risk scores

CVSS 3.1

Type
Secondary
Base score
0
Impact score
0
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
Severity
NONE

Weaknesses

cve@mitre.org
CWE-201

Social media

Hype score
Not currently trending