Vulnerabilities > CVE-2021-37213 - Authorization Bypass Through User-Controlled Key vulnerability in Larvata Flygo 1.90.5
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID and date in specific parameters to access particular employee’s check-in record.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |