Vulnerabilities > CVE-2021-36388 - Authorization Bypass Through User-Controlled Key vulnerability in Yellowfinbi Yellowfin
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4".
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
References
- https://github.com/cyberaz0r/Yellowfin-Multiple-Vulnerabilities/blob/main/README.md
- https://wiki.yellowfinbi.com/display/yfcurrent/Release+Notes+for+Yellowfin+9#ReleaseNotesforYellowfin9-Yellowfin9.6
- https://packetstormsecurity.com/files/164515/Yellowfin-Cross-Site-Scripting-Insecure-Direct-Object-Reference.html
- http://seclists.org/fulldisclosure/2021/Oct/15
- https://cyberaz0r.info/2021/10/yellowfin-multiple-vulnerabilities/