Vulnerabilities > CVE-2021-37215 - Authorization Bypass Through User-Controlled Key vulnerability in Larvata Flygo 1.90.5
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifying that employee’s ID in the API parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |