Vulnerabilities > CVE-2022-30760 - Authorization Bypass Through User-Controlled Key vulnerability in Ihb-Eg Fn2Web

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ihb-eg
CWE-639

Summary

An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint.

Vulnerable Configurations

Part Description Count
Application
Ihb-Eg
117