Vulnerabilities > CVE-2021-31927 - Authorization Bypass Through User-Controlled Key vulnerability in Annexcloud Loyalty Experience Platform
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. It was fixed in v2021.1.0.2.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |